5.4

CVSS4.0

CVE-2024-29223 -

Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“… Published: Feb. 12, 2025, 9:18 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 6:42 p.m.

7.3

CVSS4.0

CVE-2024-31858 -

Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“… Published: Feb. 12, 2025, 9:16 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

5.3

CVSS4.0

CVE-2025-0113 - Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker Containers

A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the …

πŸ“… Published: Feb. 12, 2025, 9:05 p.m. πŸ”„ Last Modified: April 9, 2025, 5:15 p.m.

7.5

CVSS4.0

CVE-2025-0110 - PAN-OS OpenConfig Plugin: Command Injection Vulnerability in OpenConfig Plugin

A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are run as the β€œ__openconf…

πŸ“… Published: Feb. 12, 2025, 9:04 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

5.3

CVSS4.0

CVE-2025-1227 - ywoa AddressDao.xml selectList sql injection

A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the p…

πŸ“… Published: Feb. 12, 2025, 9 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:39 p.m.

5.9

CVSS4.0

CVE-2025-0111 - PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the β€œnobody” user. You can greatly reduce the risk of this issue by r…

πŸ“… Published: Feb. 12, 2025, 8:58 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

2.1

CVSS4.0

CVE-2025-0109 - PAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web Interface

An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the β€œnobody” user; this includes limited logs and configuration files but does …

πŸ“… Published: Feb. 12, 2025, 8:56 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 4:19 p.m.

5.9

CVSS4.0

CVE-2025-0108 - PAN-OS: Authentication Bypass in the Management Web Interface

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP …

πŸ“… Published: Feb. 12, 2025, 8:55 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

8.5

CVSS4.0

CVE-2024-12673 -

An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V Series (Gen 5) * …

πŸ“… Published: Feb. 12, 2025, 8:31 p.m. πŸ”„ Last Modified: July 12, 2025, 10:45 p.m.

6.9

CVSS4.0

CVE-2025-1226 - ywoa setup.jsp improper authorization

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

πŸ“… Published: Feb. 12, 2025, 8:31 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:38 p.m.
Total resulsts: 343948
Page 6233 of 34,395
Β« previous page Β» next page
Filters