Latest CVE Feed
-
4.8
MEDIUMCVE-2025-3512
There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-2636
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attacke... Read more
Affected Products : instawp_connect- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Path Traversal
-
5.9
MEDIUMCVE-2025-1386
When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Denial of Service
-
3.1
LOWCVE-2025-32816
CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
5.8
MEDIUMCVE-2025-26335
Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information ... Read more
Affected Products : powerprotect_cyber_recovery- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-0128
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. R... Read more
Affected Products : pan-os- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2025-0127
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not... Read more
Affected Products : pan-os- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.3
HIGHCVE-2025-0126
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a ... Read more
Affected Products : pan-os- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-0125
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. Th... Read more
Affected Products : pan-os- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-0124
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and conf... Read more
Affected Products : pan-os- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-0122
A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Denial of Service
-
6.8
MEDIUMCVE-2025-0121
A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without C... Read more
Affected Products : cortex_xdr_agent- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2025-0120
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution re... Read more
- Published: Apr. 11, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-51461
IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources.... Read more
Affected Products : qradar_wincollect- Published: Apr. 11, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-32809
W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-32808
W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-32807
A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.... Read more
Affected Products : fusiondirectory- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
-
6.2
MEDIUMCVE-2025-29918
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite l... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
6.2
MEDIUMCVE-2025-29917
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly limited. Due to this, signatures using the keyword and setting can cause l... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-29916
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table a... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service