6.7

CVSS3.1

CVE-2024-57062 -

An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 4:43 p.m.

9.3

CVSS4.0

CVE-2025-25292 - Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely difโ€ฆ

๐Ÿ“… Published: March 12, 2025, 8:53 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

9.3

CVSS4.0

CVE-2025-25291 - ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely difโ€ฆ

๐Ÿ“… Published: March 12, 2025, 8:16 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.7

CVSS4.0

CVE-2025-25293 - ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. Itโ€ฆ

๐Ÿ“… Published: March 12, 2025, 8:11 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

8.7

CVSS4.0

CVE-2024-26290 - Authenticated Remote Command Injection affecting Avid NEXIS

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-sโ€ฆ

๐Ÿ“… Published: March 12, 2025, 7:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2025-0118 - GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerabiliโ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:36 p.m. ๐Ÿ”„ Last Modified: June 27, 2025, 4:52 p.m.

7.1

CVSS4.0

CVE-2025-0117 - GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalPrโ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-0116 - PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame

A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenanceโ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:34 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS4.0

CVE-2025-0115 - PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI

A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. You can greatly โ€ฆ

๐Ÿ“… Published: March 12, 2025, 6:30 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-22870 - HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

๐Ÿ“… Published: March 12, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344716
Page 5909 of 34,472
ยซ previous page ยป next page
Filters