CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-0134

    Last Modified: 15 Apr 2026

    A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.

    Published: 14 May 2025
    2.7
    Low

    CVE-2025-0133

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN. There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal. For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.

    Published: 14 May 2025
    6.9
    Medium

    CVE-2025-0132

    Last Modified: 15 Apr 2026

    A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

    Published: 14 May 2025
    8.3
    High

    CVE-2025-4640

    Last Modified: 15 Apr 2026

    Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.

    Published: 14 May 2025
    7.1
    High

    CVE-2025-0131

    Last Modified: 15 Apr 2026

    An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.

    Published: 14 May 2025
    8.8
    High

    CVE-2025-4639

    Last Modified: 15 Apr 2026

    CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

    Published: 14 May 2025
    9.2
    Critical

    CVE-2025-4638

    Last Modified: 21 Oct 2025

    A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.

    Published: 14 May 2025
    8.7
    High

    CVE-2025-4637

    Last Modified: 15 Apr 2026

    Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.

    Published: 14 May 2025
    4.3
    Medium

    CVE-2025-46786

    Last Modified: 6 Nov 2025

    Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.

    Published: 14 May 2025
    4.3
    Medium

    CVE-2025-4664

    Last Modified: 6 Jun 2025

    Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-46785

    Last Modified: 19 Aug 2025

    Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-30668

    Last Modified: 4 Nov 2025

    Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 May 2025
    8.2
    High

    CVE-2025-0130

    Last Modified: 29 May 2026

    A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-30667

    Last Modified: 4 Nov 2025

    NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-30666

    Last Modified: 5 Aug 2025

    NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-30665

    Last Modified: 5 Aug 2025

    NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 May 2025
    6.6
    Medium

    CVE-2025-30664

    Last Modified: 26 Feb 2026

    Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 14 May 2025
    8.8
    High

    CVE-2025-30663

    Last Modified: 26 Feb 2026

    Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 14 May 2025
    7.4
    High

    CVE-2025-47710

    Last Modified: 10 Jun 2025

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-47709

    Last Modified: 10 Jun 2025

    Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

    Published: 14 May 2025
    8.8
    High

    CVE-2025-47708

    Last Modified: 10 Jun 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-47707

    Last Modified: 10 Jun 2025

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

    Published: 14 May 2025
    4.8
    Medium

    CVE-2025-47706

    Last Modified: 10 Jun 2025

    Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-47705

    Last Modified: 10 Feb 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 2.0.0 before 2.0.5, from 7.X-1.0 through 7.X-1.5, from 1.0 through 1.2.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-47704

    Last Modified: 10 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-47703

    Last Modified: 10 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-47702

    Last Modified: 10 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 before 2.2.2.

    Published: 14 May 2025
    8.8
    High

    CVE-2025-47701

    Last Modified: 25 Jun 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0.

    Published: 14 May 2025
    5.4
    Medium

    CVE-2025-3877

    Last Modified: 11 Jun 2025

    This CVE was marked as fixed, but due to other code landing - was not actually fixed. It was subsequently fixed in CVE-2025-5986.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-3932

    Last Modified: 22 Apr 2026

    It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

    Published: 14 May 2025
    8.1
    High

    CVE-2025-3909

    Last Modified: 20 Apr 2026

    Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, allowing the embedded JavaScript to run without requiring a file download. This behavior relies on Thunderbird auto-saving the attachment to /tmp and linking to it via the file:/// protocol, potentially enabling JavaScript execution as part of the HTML. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-3875

    Last Modified: 20 Apr 2026

    Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the actual address. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

    Published: 14 May 2025
    7.2
    High

    CVE-2025-40595

    Last Modified: 15 Apr 2026

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

    Published: 14 May 2025
    8.9
    High

    CVE-2025-47782

    Last Modified: 15 Apr 2026

    motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin user credentials to execute any command within a non-interactive shell as motionEye run user, `motion` by default. The vulnerability has been patched with motionEye v0.43.1b4. As a workaround, apply the patch manually.

    Published: 14 May 2025
    9.8
    Critical

    CVE-2025-47781

    Last Modified: 6 Nov 2025

    Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. When a user attempts to login to the application, they insert their email and a 6 digit code is sent to their email address to complete the authentication. A token that consists of 6 digits only presents weak entropy however and when coupled with no token brute force protection, makes it possible for an unauthenticated attacker with knowledge of a valid email address to successfully brute force the token within 15 minutes (token expiration time) and take over the account associated with the targeted email address. All users on the Rallly applications are impacted. As long as an attacker knows the user's email address they used to register on the app, they can systematically take over any user account. For the authentication mechanism to be safe, the token would need to be assigned a complex high entropy value that cannot be bruteforced within reasonable time, and ideally rate limiting the /api/auth/callback/email endpoint to further make brute force attempts unreasonable within the 15 minutes time. As of time of publication, no patched versions are available.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-47778

    Last Modified: 15 Apr 2026

    Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file `src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php` manually.

    Published: 14 May 2025
    9.6
    Critical

    CVE-2025-47777

    Last Modified: 22 Jan 2026

    5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. All users of 5ire client versions prior to patched releases, particularly those interacting with untrusted chatbots or pasting external content, are affected. Version 0.11.1 contains a patch for the issue.

    Published: 14 May 2025
    6.2
    Medium

    CVE-2025-47775

    Last Modified: 11 Jul 2025

    Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.

    Published: 14 May 2025
    5
    Medium

    CVE-2025-24969

    Last Modified: 5 Aug 2025

    iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

    Published: 14 May 2025
    4.3
    Medium

    CVE-2025-24785

    Last Modified: 1 Aug 2025

    iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided layout_class before saving the dashboard.

    Published: 14 May 2025
    5.3
    Medium

    CVE-2025-24026

    Last Modified: 1 Aug 2025

    iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a workaround, if iTop app_root_url is defined in the configuration file, then there is no possible way to exploit this ReDoS.

    Published: 14 May 2025
    8.5
    High

    CVE-2025-24022

    Last Modified: 20 Jan 2026

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.

    Published: 14 May 2025
    5
    Medium

    CVE-2025-24021

    Last Modified: 26 Aug 2025

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.

    Published: 14 May 2025
    6.3
    Medium

    CVE-2024-56157

    Last Modified: 1 Aug 2025

    iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1. As a workaround, check CSV content before importing it.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2024-52601

    Last Modified: 1 Aug 2025

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.

    Published: 14 May 2025
    9.4
    Critical

    CVE-2024-10865

    Last Modified: 15 Apr 2026

    Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.

    Published: 14 May 2025
    7.5
    High

    CVE-2024-10864

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5

    Published: 14 May 2025
    7.5
    High

    CVE-2025-3600

    Last Modified: 30 Sept 2025

    In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.

    Published: 14 May 2025
    6
    Medium

    CVE-2025-47436

    Last Modified: 14 Jul 2025

    Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption. This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1. Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-47445

    Last Modified: 23 Apr 2026

    Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.

    Published: 14 May 2025