Latest CVE Feed
-
4.8
MEDIUMCVE-2025-0137
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. Th... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-0136
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall th... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Cryptography
-
5.2
MEDIUMCVE-2025-0135
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and... Read more
- Published: May. 14, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-0134
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.... Read more
Affected Products : cortex_xdr_broker_vm- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-0133
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when t... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-0132
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.... Read more
Affected Products : cortex_xdr_broker_vm- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-0131
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileg... Read more
Affected Products : metadefender_endpoint_security_sdk- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-4639
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: XML External Entity
-
9.2
CRITICALCVE-2025-4638
A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since ver... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
8.7
HIGHCVE-2025-4637
Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-46786
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-46785
Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30668
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30667
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30666
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30665
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-30664
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-30663
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
8.2
HIGHCVE-2025-0130
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Re... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service