Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2025-0108
Known exploited
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
CVSS Score
9.1
EPSS Score
0.934
Published
2025-02-12
CVE-2025-0111
Known exploited
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.
CVSS Score
6.5
EPSS Score
0.05
Published
2025-02-12
CVE-2025-21418
Known exploited
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.074
Published
2025-02-11
CVE-2025-21391
Known exploited
Windows Storage Elevation of Privilege Vulnerability
CVSS Score
7.1
EPSS Score
0.043
Published
2025-02-11
CVE-2025-24472
Known exploited
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
CVSS Score
8.1
EPSS Score
0.086
Published
2025-02-11
CVE-2025-24200
Known exploited
An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CVSS Score
6.1
EPSS Score
0.303
Published
2025-02-10
CVE-2025-0994
Known exploited
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
CVSS Score
8.8
EPSS Score
0.724
Published
2025-02-06
CVE-2024-40890
Known exploited
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
CVSS Score
8.8
EPSS Score
0.192
Published
2025-02-04
CVE-2024-40891
Known exploited
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
CVSS Score
8.8
EPSS Score
0.365
Published
2025-02-04
CVE-2025-25181
Known exploited
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
CVSS Score
5.8
EPSS Score
0.21
Published
2025-02-03


Contact Us

Shodan ® - All rights reserved