6.1

CVSS3.1

CVE-2025-28011 -

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 8 p.m.

5.4

CVSS3.1

CVE-2025-25625 -

A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML and Javascript on thโ€ฆ

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 6:26 p.m.

6.7

CVSS3.1

CVE-2024-57062 -

An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 4:43 p.m.

9.3

CVSS4.0

CVE-2025-25292 - Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely difโ€ฆ

๐Ÿ“… Published: March 12, 2025, 8:53 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

9.3

CVSS4.0

CVE-2025-25291 - ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely difโ€ฆ

๐Ÿ“… Published: March 12, 2025, 8:16 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.7

CVSS4.0

CVE-2025-25293 - ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. Itโ€ฆ

๐Ÿ“… Published: March 12, 2025, 8:11 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

8.7

CVSS4.0

CVE-2024-26290 - Authenticated Remote Command Injection affecting Avid NEXIS

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-sโ€ฆ

๐Ÿ“… Published: March 12, 2025, 7:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2025, 11:15 p.m.

6

CVSS4.0

CVE-2025-0118 - GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerabiliโ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:36 p.m. ๐Ÿ”„ Last Modified: June 27, 2025, 4:52 p.m.

7.1

CVSS4.0

CVE-2025-0117 - GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalPrโ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:35 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.8

CVSS4.0

CVE-2025-0116 - PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame

A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenanceโ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:34 p.m. ๐Ÿ”„ Last Modified: March 18, 2025, 12:15 a.m.
Total resulsts: 343947
Page 5832 of 34,395
ยซ previous page ยป next page
Filters