9.1

CVSS3.1

CVE-2025-47884 -

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a tru…

📅 Published: May 14, 2025, 8:35 p.m. 🔄 Last Modified: June 12, 2025, 1:48 p.m.

4.4

CVSS3.1

CVE-2025-33104 - IBM WebSphere Application Server cross

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: May 14, 2025, 7:01 p.m. 🔄 Last Modified: Aug. 20, 2025, 3:47 p.m.

7.5

CVSS3.1

CVE-2025-2900 - IBM Semeru Runtime denial of service

IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.

📅 Published: May 14, 2025, 6:50 p.m. 🔄 Last Modified: Aug. 28, 2025, 2:12 p.m.

5.3

CVSS4.0

CVE-2025-0136 - PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devices

Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec. This issue does not affect Clo…

📅 Published: May 14, 2025, 6:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-0138 - Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Interface

Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.

📅 Published: May 14, 2025, 6:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-0137 - PAN-OS: Improper Neutralization of Input in the Management Web Interface

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the m…

📅 Published: May 14, 2025, 6:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-4641 - XML External Entity (XXE) injection vulnerability in WebDriverManager

Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/gith…

📅 Published: May 14, 2025, 6:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-0135 - GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

📅 Published: May 14, 2025, 6:08 p.m. 🔄 Last Modified: June 27, 2025, 4:50 p.m.

6.5

CVSS4.0

CVE-2025-0134 - Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM

A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS4.0

CVE-2025-0133 - PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The p…

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344718
Page 4963 of 34,472
« previous page » next page
Filters