6.5
CVE-2025-30668 - Zoom Workplace Apps - NULL Pointer Dereference
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.
8.2
CVE-2025-0130 - PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafteโฆ
A missing exception check in Palo Alto Networks PAN-OSยฎ software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this cโฆ
6.5
CVE-2025-30667 - Zoom Workplace Apps - NULL Pointer Dereference
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
6.5
CVE-2025-30666 - Zoom Workplace Apps for Windows - NULL Pointer Dereference
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
6.5
CVE-2025-30665 - Zoom Workplace Apps for Windows - NULL Pointer Dereference
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
6.6
CVE-2025-30664 - Zoom Workplace Apps - Cross-site Scripting
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
8.8
CVE-2025-30663 - Zoom Workplace Apps - Time-of-check Time-of-use
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
7.4
CVE-2025-47710 - Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-056
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
6.5
CVE-2025-47709 - Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-055
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
8.8
CVE-2025-47708 - Enterprise MFA - TFA for Drupal - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-054
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.