7.1

CVSS4.0

CVE-2025-0127 - PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed.…

📅 Published: April 11, 2025, 2:01 a.m. 🔄 Last Modified: April 11, 2025, 4:01 p.m.

8.3

CVSS4.0

CVE-2025-0126 - PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login

When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. Th…

📅 Published: April 11, 2025, 1:57 a.m. 🔄 Last Modified: April 11, 2025, 4:02 p.m.

5.8

CVSS4.0

CVE-2025-0125 - PAN-OS: Improper Neutralization of Input in the Management Web Interface

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the m…

📅 Published: April 11, 2025, 1:56 a.m. 🔄 Last Modified: April 11, 2025, 4:02 p.m.

2.1

CVSS4.0

CVE-2025-0124 - PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface

An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system …

📅 Published: April 11, 2025, 1:55 a.m. 🔄 Last Modified: Oct. 2, 2025, 3:16 p.m.

5.1

CVSS4.0

CVE-2025-0122 - Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through Burst of Crafted Packets

A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device.

📅 Published: April 11, 2025, 1:48 a.m. 🔄 Last Modified: April 11, 2025, 4:02 p.m.

6.8

CVSS4.0

CVE-2025-0121 - Cortex XDR Agent: Local Windows User Can Crash the Agent

A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.

📅 Published: April 11, 2025, 1:45 a.m. 🔄 Last Modified: April 11, 2025, 4:02 p.m.

7.1

CVSS4.0

CVE-2025-0120 - GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successf…

📅 Published: April 11, 2025, 1:44 a.m. 🔄 Last Modified: June 27, 2025, 4:51 p.m.

5.8

CVSS3.1

CVE-2025-26335 -

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

📅 Published: April 11, 2025, 1:20 a.m. 🔄 Last Modified: Jan. 14, 2026, 2:33 p.m.

4.3

CVSS3.1

CVE-2024-51461 - IBM QRadar WinCollect Agent denial of service

IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources.

📅 Published: April 11, 2025, 1:13 a.m. 🔄 Last Modified: Sept. 1, 2025, 12:54 a.m.

8.6

CVSS3.1

CVE-2025-32367 -

The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object Reference. NOTE: the number 4.0.8 was used for both the unpatched and patched versions.

📅 Published: April 11, 2025, midnight 🔄 Last Modified: April 15, 2025, 6:39 p.m.
Total resulsts: 342251
Page 5220 of 34,226
« previous page » next page
Filters