2.7

CVSS4.0

CVE-2025-0133 - PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The p…

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0132 - Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services

A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-4640 - Out-of-bounds Write in pcl

Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or…

📅 Published: May 14, 2025, 6:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-0131 - GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Sec…

An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, executio…

📅 Published: May 14, 2025, 6:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-4639 - Improper Restriction of XML External Entity Reference in Peergos

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

📅 Published: May 14, 2025, 6:04 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-4638 - Improper Pointer Arithmetic in pcl

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by default uses a zlib inst…

📅 Published: May 14, 2025, 5:59 p.m. 🔄 Last Modified: Oct. 21, 2025, 2:10 p.m.

8.7

CVSS4.0

CVE-2025-4637 - Divide By Zero in dlib

Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.

📅 Published: May 14, 2025, 5:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-46786 - Zoom Workplace Apps - Cross-site Scripting

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.

📅 Published: May 14, 2025, 5:42 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:51 p.m.

4.3

CVSS3.1

CVE-2025-4664 -

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

📅 Published: May 14, 2025, 5:41 p.m. 🔄 Last Modified: June 6, 2025, 1 a.m.

6.5

CVSS3.1

CVE-2025-46785 - Zoom Workplace Apps for Windows - Buffer Over-read

Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

📅 Published: May 14, 2025, 5:41 p.m. 🔄 Last Modified: Aug. 19, 2025, 7:14 p.m.
Total resulsts: 346099
Page 5102 of 34,610
« previous page » next page
Filters