9.3

CVSS4.0

CVE-2025-4641 - XML External Entity (XXE) injection vulnerability in WebDriverManager

Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/gith…

📅 Published: May 14, 2025, 6:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-0135 - GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect App

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

📅 Published: May 14, 2025, 6:08 p.m. 🔄 Last Modified: June 27, 2025, 4:50 p.m.

6.5

CVSS4.0

CVE-2025-0134 - Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM

A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS4.0

CVE-2025-0133 - PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The p…

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0132 - Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services

A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

📅 Published: May 14, 2025, 6:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-4640 - Out-of-bounds Write in pcl

Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or…

📅 Published: May 14, 2025, 6:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-0131 - GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Sec…

An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, executio…

📅 Published: May 14, 2025, 6:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-4639 - Improper Restriction of XML External Entity Reference in Peergos

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

📅 Published: May 14, 2025, 6:04 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-4638 - Improper Pointer Arithmetic in pcl

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by default uses a zlib inst…

📅 Published: May 14, 2025, 5:59 p.m. 🔄 Last Modified: Oct. 21, 2025, 2:10 p.m.

8.7

CVSS4.0

CVE-2025-4637 - Divide By Zero in dlib

Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.

📅 Published: May 14, 2025, 5:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346142
Page 5106 of 34,615
« previous page » next page
Filters