7.2

CVSS3.1

CVE-2025-3434 - SMTP for Amazon SES – YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs

The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

📅 Published: April 11, 2025, 8:21 a.m. 🔄 Last Modified: April 11, 2025, 3:39 p.m.

8

CVSS3.0

CVE-2025-32107 -

OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device.

📅 Published: April 11, 2025, 8:17 a.m. 🔄 Last Modified: April 11, 2025, 3:39 p.m.

4.8

CVSS4.0

CVE-2025-3512 - Buffer overflow in QTextMarkdownImporter

There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix is…

📅 Published: April 11, 2025, 7:39 a.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

5.9

CVSS4.0

CVE-2025-1386 - Query smuggling in ch-go library

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.

📅 Published: April 11, 2025, 4:27 a.m. 🔄 Last Modified: Dec. 19, 2025, 6:47 p.m.

9.8

CVSS3.1

CVE-2025-2636 - InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on…

📅 Published: April 11, 2025, 4:21 a.m. 🔄 Last Modified: April 11, 2025, 4:01 p.m.

5.3

CVSS4.0

CVE-2025-0128 - PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes…

📅 Published: April 11, 2025, 2:03 a.m. 🔄 Last Modified: April 11, 2025, 4:01 p.m.

7.1

CVSS4.0

CVE-2025-0127 - PAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-Series

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed.…

📅 Published: April 11, 2025, 2:01 a.m. 🔄 Last Modified: April 11, 2025, 4:01 p.m.

8.3

CVSS4.0

CVE-2025-0126 - PAN-OS: Session Fixation Vulnerability in GlobalProtect SAML Login

When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. Th…

📅 Published: April 11, 2025, 1:57 a.m. 🔄 Last Modified: April 11, 2025, 4:02 p.m.

5.8

CVSS4.0

CVE-2025-0125 - PAN-OS: Improper Neutralization of Input in the Management Web Interface

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the m…

📅 Published: April 11, 2025, 1:56 a.m. 🔄 Last Modified: April 11, 2025, 4:02 p.m.

2.1

CVSS4.0

CVE-2025-0124 - PAN-OS: Authenticated File Deletion Vulnerability on the Management Web Interface

An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system …

📅 Published: April 11, 2025, 1:55 a.m. 🔄 Last Modified: Oct. 2, 2025, 3:16 p.m.
Total resulsts: 342307
Page 5225 of 34,231
« previous page » next page
Filters