Month: May 2025

[Palo Alto Networks Security Advisories] CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Featurevia a Burst of Maliciously Crafted Packets

Palo Alto Networks Security Advisories /CVE-2025-0130CVE-2025-0130 PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted...

[Palo Alto Networks Security Advisories] PAN-SA-2025-0009 Chromium: Monthly Vulnerability Update (May 2025)

Palo Alto Networks Security Advisories /PAN-SA-2025-0009PAN-SA-2025-0009 Chromium: Monthly Vulnerability Update (May 2025)UrgencyMODERATE047910Severity7.6 ·HIGHExploit MaturityUNREPORTEDResponse EffortLOWRecoveryUSERValue DensityDIFFUSEAttack VectorNETWORKAttack ComplexityLOWAttack RequirementsNONEAutomatableNOUser InteractionACTIVEProduct...

[Palo Alto Networks Security Advisories] CVE-2025-0134 Cortex XDR Broker VM: Authenticated Code Injection Vulnerabilityin Broker VM

Palo Alto Networks Security Advisories /CVE-2025-0134CVE-2025-0134 Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VMUrgencyMODERATE047910Severity2.6 ·LOWExploit MaturityUNREPORTEDResponse EffortMODERATERecoveryUSERValue...

[Palo Alto Networks Security Advisories] CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management WebInterface

Palo Alto Networks Security Advisories /CVE-2025-0137CVE-2025-0137 PAN-OS: Improper Neutralization of Input in the Management Web InterfaceUrgencyMODERATE047910Severity1.1 ·LOWExploit MaturityUNREPORTEDResponse EffortMODERATERecoveryUSERValue DensityCONCENTRATEDAttack...

[Palo Alto Networks Security Advisories] CVE-2025-0132 Cortex XDR Broker VM: Unauthenticated User Can Disable InternalServices

Palo Alto Networks Security Advisories /CVE-2025-0132CVE-2025-0132 Cortex XDR Broker VM: Unauthenticated User Can Disable Internal ServicesUrgencyMODERATE047910Severity2.7 ·LOWExploit MaturityUNREPORTEDResponse EffortMODERATERecoveryUSERValue DensityCONCENTRATEDAttack...

BugCrowd Bug Bounty Disclosure: P3 – Exposed Python Script with Hardcoded SFTP Credentials, Internal IPs, and Sensitive Data Access – unknown_soldier

Exposed Python Script with Hardcoded SFTP Credentials, Internal IPs, and Sensitive Data Access Exposed Python Script with Hardcoded SFTP Credentials,...

BugCrowd Bug Bounty Disclosure: P5 – Improper Access Control: Authenticated Resource Exposed via Wayback Machine Archive- Nasa sheets& docs – RootVaibhav

Improper Access Control: Authenticated Resource Exposed via Wayback Machine Archive- Nasa sheets& docs Improper Access Control: Authenticated Resource Exposed via...

BugCrowd Bug Bounty Disclosure: P5 – EXIF Geolocation Data Not Stripped in NASA CDSCC Image – Exposure of Sensitive Location (Canberra Deep Space Communication Complex) – Faxcel

EXIF Geolocation Data Not Stripped in NASA CDSCC Image - Exposure of Sensitive Location (Canberra Deep Space Communication Complex) EXIF...

BugCrowd Bug Bounty Disclosure: P5 – Public Exposure of Internal Calibration Planning File on heasarc.gsfc.nasa.gov (XMM-Newton) – JustAKids

Public Exposure of Internal Calibration Planning File on heasarc.gsfc.nasa.gov (XMM-Newton) Public Exposure of Internal Calibration Planning File on heasarc.gsfc.nasa.gov (XMM-Newton)...

BugCrowd Bug Bounty Disclosure: P5 – Public Exposure of Internal Calibration Planning File on heasarc.gsfc.nasa.gov (XMM-Newton) – JustAKids

Public Exposure of Internal Calibration Planning File on heasarc.gsfc.nasa.gov (XMM-Newton) Public Exposure of Internal Calibration Planning File on heasarc.gsfc.nasa.gov (XMM-Newton)...