8.1

CVSS3.1

CVE-2025-22236 - CVE-2025-22236 salt advisory

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

๐Ÿ“… Published: June 13, 2025, 6:53 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-38825 - CVE-2024-38825 Salt Advisory

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need access to the corresponding private key for the authentication aโ€ฆ

๐Ÿ“… Published: June 13, 2025, 6:46 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-38823 - CVE-2024-38823 Salt Advisory

Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.

๐Ÿ“… Published: June 13, 2025, 6:41 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-5923 - Game Review Block <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via classNameโ€ฆ

The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜classNameโ€™ parameter in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acโ€ฆ

๐Ÿ“… Published: June 13, 2025, 6:41 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 8:30 p.m.

2.7

CVSS3.1

CVE-2024-38822 - CVE-2024-38822 Salt Advisory

Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.

๐Ÿ“… Published: June 13, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

1

CVSS4.0

CVE-2025-4227 - GlobalProtect App: Interception in Endpoint Traffic Policy Enforcement

An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-new-features/new-features-released-in-gp-app/endpoint-traffic-policy-enforcement feature of the Palo Alto Networks GlobalProtectโ„ข app allows ceโ€ฆ

๐Ÿ“… Published: June 13, 2025, 5:50 a.m. ๐Ÿ”„ Last Modified: June 27, 2025, 4:49 p.m.

6

CVSS4.0

CVE-2025-4229 - PAN-OS: Traffic Information Disclosure Vulnerability

An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OSยฎ software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW โ€ฆ

๐Ÿ“… Published: June 13, 2025, 5:42 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-6046 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: June 13, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 11:15 p.m.

7.5

CVSS3.1

CVE-2025-5282 - WP Travel Engine <= 6.5.1 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

The WP Travel Engine โ€“ Tour Booking Plugin โ€“ Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for unauthenticated attackers toโ€ฆ

๐Ÿ“… Published: June 13, 2025, 3:41 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:30 a.m.

5.3

CVSS3.1

CVE-2025-5815 - Traffic Monitor <= 3.2.2 - Missing Authorization to Unauthenticated Settings Update

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.

๐Ÿ“… Published: June 13, 2025, 3:41 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:30 a.m.
Total resulsts: 349182
Page 5036 of 34,919
ยซ previous page ยป next page
Filters