5.9

CVSS4.0

CVE-2025-0108 - PAN-OS: Authentication Bypass in the Management Web Interface

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP …

πŸ“… Published: Feb. 12, 2025, 8:55 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

8.5

CVSS4.0

CVE-2024-12673 -

An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V Series (Gen 5) * …

πŸ“… Published: Feb. 12, 2025, 8:31 p.m. πŸ”„ Last Modified: July 12, 2025, 10:45 p.m.

6.9

CVSS4.0

CVE-2025-1226 - ywoa setup.jsp improper authorization

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

πŸ“… Published: Feb. 12, 2025, 8:31 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:38 p.m.

5.3

CVSS4.0

CVE-2025-1225 - ywoa WXCallBack Interface XMLParse.java extract xml external entity reference

A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference…

πŸ“… Published: Feb. 12, 2025, 8 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:39 p.m.

5.3

CVSS4.0

CVE-2025-1224 - ywoa UserMapper.xml listNameBySql sql injection

A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to th…

πŸ“… Published: Feb. 12, 2025, 7:31 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:37 p.m.

5.3

CVSS4.0

CVE-2025-1216 - ywoa OaNoticeMapper.xml selectNoticeList sql injection

A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely.…

πŸ“… Published: Feb. 12, 2025, 7 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:38 p.m.

7.1

CVSS3.1

CVE-2025-0937 - Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

πŸ“… Published: Feb. 12, 2025, 6:59 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:07 p.m.

2.4

CVSS4.0

CVE-2025-1215 - vim main.c memory corruption

A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able …

πŸ“… Published: Feb. 12, 2025, 6:31 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 5:28 p.m.

8.1

CVSS3.1

CVE-2025-1146 - CrowdStrike Falcon Sensor for Linux TLS Issue

CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where o…

πŸ“… Published: Feb. 12, 2025, 6:27 p.m. πŸ”„ Last Modified: June 17, 2025, 12:08 p.m.

7.5

CVSS3.1

CVE-2025-25283 - parse-duraton vulnerable to Regex Denial of Service that results in event loop delay and out of mem…

parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1.3 are vulnerable to an event loop delay due to the CPU-bound operation of resolving the provided string, from a 0.5ms and up to ~50ms per one operation, with a varying size from 0…

πŸ“… Published: Feb. 12, 2025, 6:21 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 7:25 p.m.
Total resulsts: 344111
Page 6250 of 34,412
Β« previous page Β» next page
Filters