2

CVSS4.0

CVE-2025-0138 - Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Interface

Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.

📅 Published: May 14, 2025, 6:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-0137 - PAN-OS: Improper Neutralization of Input in the Management Web Interface

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the m…

📅 Published: May 14, 2025, 6:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-4641 - XML External Entity (XXE) injection vulnerability in WebDriverManager

Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/gith…

📅 Published: May 14, 2025, 6:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-0135 - GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

📅 Published: May 14, 2025, 6:08 p.m. 🔄 Last Modified: June 27, 2025, 4:50 p.m.

6.5

CVSS4.0

CVE-2025-0134 - Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM

A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS4.0

CVE-2025-0133 - PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The p…

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0132 - Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services

A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-4640 - Out-of-bounds Write in pcl

Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or…

📅 Published: May 14, 2025, 6:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-0131 - GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Sec…

An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, executio…

📅 Published: May 14, 2025, 6:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-4639 - Improper Restriction of XML External Entity Reference in Peergos

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

📅 Published: May 14, 2025, 6:04 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346094
Page 5101 of 34,610
« previous page » next page
Filters