9.3
CVE-2025-0129 - Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
6.7
CVE-2024-11679 -
An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.
0
CVE-2025-0123 - PAN-OS: Information Disclosure Vulnerability in HTTP/2 Packet Captures
A vulnerability in the Palo Alto Networks PAN-OSยฎ software enables unlicensed administrators to view clear-text data captured using the packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture in decrypted HTTP/โฆ
6.3
CVE-2025-0119 - Cortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VM
A command injection vulnerabilityย in the Palo Alto Networks Cortex XDRยฎ Broker VMย allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
6.9
CVE-2025-32077 - XSSes in Extension:SimpleCalendar
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Extension:SimpleCalendar allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Extension:SimpleCalendar: from 1.39 through 1.43.
6.9
CVE-2025-32078 - XSSes and potential RCE in Special:VersionCompare
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Version Compare Extension: from 1.39 through 1.43.
6.5
CVE-2025-32079 - Saving the right content to MediaWiki:GrowthMentors.json can take down the site
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments allows HTTP DoS.This issue affects Mediawiki - GrowthExperiments: from 1.39 through 1.43.
6.9
CVE-2025-32080 - Cross-origin data leak in mobilefrontend via lazy load images
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Shared Resource Manipulation.This issue affects Mediawiki - Mobile Frontend Extension: from 1.39 through 1.43.
6.9
CVE-2025-32076 - Evil regex used to process user-provided data in VisualData
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Visual Data Extension allows HTTP DoS.This issue affects Mediawiki - Visual Data Extension: from 1.39 through 1.43.
6.9
CVE-2025-32072 - HTML injection in feed output from i18n message
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.