8.1
CVE-2025-22236 - CVE-2025-22236 salt advisory
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
6.4
CVE-2024-38825 - CVE-2024-38825 Salt Advisory
The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need access to the corresponding private key for the authentication aโฆ
2.7
CVE-2024-38823 - CVE-2024-38823 Salt Advisory
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
6.4
CVE-2025-5923 - Game Review Block <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via classNameโฆ
The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โclassNameโ parameter in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acโฆ
2.7
CVE-2024-38822 - CVE-2024-38822 Salt Advisory
Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.
1
CVE-2025-4227 - GlobalProtect App: Interception in Endpoint Traffic Policy Enforcement
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-new-features/new-features-released-in-gp-app/endpoint-traffic-policy-enforcement feature of the Palo Alto Networks GlobalProtectโข app allows ceโฆ
6
CVE-2025-4229 - PAN-OS: Traffic Information Disclosure Vulnerability
An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OSยฎ software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW โฆ
0.0
CVE-2025-6046 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
7.5
CVE-2025-5282 - WP Travel Engine <= 6.5.1 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
The WP Travel Engine โ Tour Booking Plugin โ Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for unauthenticated attackers toโฆ
5.3
CVE-2025-5815 - Traffic Monitor <= 3.2.2 - Missing Authorization to Unauthenticated Settings Update
The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.