Month: May 2025

HackerOne Bug Bounty Disclosure: -xenoblade-chronicles-x-definitive-edition-improper-validation-of-names-allows-injecting-formatting-tags-and-bypassing-profanity-filter-roccodev

Company Name: Nintendo Company HackerOne URL: https://hackerone.com/nintendo Submitted By:roccodevLink to Submitters Profile:https://hackerone.com/roccodev Report Title: Improper validation of names allows injecting...

HackerOne Bug Bounty Disclosure: weak-rate-limiting-controls-in-the-login-page-expose-system-to-brute-force-and-dos-attacks-hajjaj

Company Name: Lichess Company HackerOne URL: https://hackerone.com/lichess Submitted By:hajjaj-Link to Submitters Profile:https://hackerone.com/hajjaj- Report Title:Weak Rate Limiting Controls in the (LOGIN)...

HackerOne Bug Bounty Disclosure: corrupted-pointer-in-node-fs-readfileutf-const-functioncallbackinfo-value-args-when-args-is-a-string-justinnietzel

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:justinnietzelLink to Submitters Profile:https://hackerone.com/justinnietzel Report Title:Corrupted pointer in node::fs::ReadFileUtf8(const FunctionCallbackInfo& args) when...

HackerOne Bug Bounty Disclosure: -xenoblade-chronicles-x-definitive-edition-unrestricted-rpcs-allow-dos-and-writing-arbitrary-flags-remotely-roccodev

Company Name: Nintendo Company HackerOne URL: https://hackerone.com/nintendo Submitted By:roccodevLink to Submitters Profile:https://hackerone.com/roccodev Report Title: Unrestricted RPCs allow DoS and writing...

HackerOne Bug Bounty Disclosure: open-redirect-vulnerability-in-oauth-flow-leading-to-potential-phishing-attack-delsec

Company Name: Lichess Company HackerOne URL: https://hackerone.com/lichess Submitted By:delsec_Link to Submitters Profile:https://hackerone.com/delsec_ Report Title:Open Redirect Vulnerability in OAuth Flow Leading...

[Palo Alto Networks Security Advisories] PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack onPAN-OS

Palo Alto Networks Security Advisories /PAN-SA-2025-0010PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OSInformationalJSONCSAF Published2025-05-14 Updated2025-05-14ReferencePAN-243431DiscoveredinternallyDescriptionThe Palo Alto...

[Palo Alto Networks Security Advisories] CVE-2025-0133 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability inGlobalProtect Gateway and Portal

Palo Alto Networks Security Advisories /CVE-2025-0133CVE-2025-0133 PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and PortalUrgencyMODERATE047910Severity2 ·LOWExploit MaturityPOCResponse EffortN/ARecoveryUSERValue...

[Palo Alto Networks Security Advisories] CVE-2025-0138 Prisma Cloud Compute Edition: Insufficient Session ExpirationVulnerability in the Web Interface

Palo Alto Networks Security Advisories /CVE-2025-0138CVE-2025-0138 Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web InterfaceUrgencyMODERATE047910Severity0.3 ·LOWExploit MaturityUNREPORTEDResponse...

[Palo Alto Networks Security Advisories] CVE-2025-0136 PAN-OS: Unencrypted Data Transfer when using AES-128-CCM onIntel-based hardware devices

Palo Alto Networks Security Advisories /CVE-2025-0136CVE-2025-0136 PAN-OS: Unencrypted Data Transfer when using AES-128-CCM on Intel-based hardware devicesUrgencyMODERATE047910Severity1.3 ·LOWExploit MaturityUNREPORTEDResponse EffortMODERATERecoveryUSERValue...

[Palo Alto Networks Security Advisories] CVE-2025-0131 GlobalProtect App: Incorrect Privilege Management Vulnerability inOPSWAT MetaDefender Endpoint Security SDK

Palo Alto Networks Security Advisories /CVE-2025-0131CVE-2025-0131 GlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Security SDKUrgencyMODERATE047910Severity4 ·MEDIUMExploit MaturityUNREPORTEDResponse...

[Palo Alto Networks Security Advisories] CVE-2025-0135 GlobalProtect App on macOS: Non Admin User Can Disable theGlobalProtect App

Palo Alto Networks Security Advisories /CVE-2025-0135CVE-2025-0135 GlobalProtect App on macOS: Non Admin User Can Disable the GlobalProtect AppUrgencyMODERATE047910Severity1.8 ·LOWExploit MaturityUNREPORTEDResponse...