NA - CVE-2025-25774 - An issue was discovered in Open5GS v2.7.2. When...
An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine,...
NA - CVE-2025-27017 - Apache NiFi 1.13.0 through 2.2.0 includes the...
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized...
NA - CVE-2025-0114 - A Denial of Service (DoS) vulnerability in the...
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large...
NA - CVE-2025-0115 - A vulnerability in the Palo Alto Networks...
A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. This issue does not affect Cloud NGFW or Prisma Access.
NA - CVE-2025-0116 - A Denial of Service (DoS) vulnerability in Palo...
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated...
NA - CVE-2025-0117 - A reliance on untrusted input for a security...
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their...
NA - CVE-2025-0118 - A vulnerability in the Palo Alto Networks...
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the...
NA - CVE-2025-22870 - Matching of hosts against proxy patterns can...
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to...
NA - CVE-2025-27407 - graphql-ruby is a Ruby implementation of...
graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema...