CVE-2025-23016 – FastCGI fcgi2 Buffer Overflow

The following table lists the changes that have been made to the CVE-2025-23016 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 10, 2025 Action […]

CVE-2024-13318 – “WP Real Estate Unauthorized Access Denial of Service”

CVE ID : CVE-2024-13318 Published : Jan. 10, 2025, 12:15 p.m. | 35 minutes ago Description : The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to […]

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey’s Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity vulnerability, tr … Read more Published Date: Jan 10, 2025 (3 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-49415 […]

Tripwire Patch Priority Index for December 2024

Tripwire Patch Priority Index for December 2024 Tripwire’s December 2024 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft and Adobe.First on the list is a notice about Windows Common Log File System Driver (CLFS). … Read more Published Date: Jan 10, 2025 (2 hours, 15 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-49142 […]

CrowdStrike Warns of Phishing Scam Targeting Job Seekers with XMRig Cryptominer

CrowdStrike Warns of Phishing Scam Targeting Job Seekers with XMRig Cryptominer Cybersecurity company CrowdStrike is alerting of a phishing campaign that exploits its own branding to distribute a cryptocurrency miner that’s disguised as an employee CRM application as part of a su … Read more Published Date: Jan 10, 2025 (3 hours, 41 minutes ago) Vulnerabilities has […]

CVE-2024-13183 – “Orbit Fox by ThemeIsle Stored Cross-Site Scripting Vulnerability”

CVE ID : CVE-2024-13183 Published : Jan. 10, 2025, 8:15 a.m. | 31 minutes ago Description : The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible for […]

January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance

January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance Welcome to 2025 and a new year of patch excitement! In my December article, I talked about Microsoft’s Secure Future Initiative (SFI) and how it manifested in many of the Microsoft products released i … Read more Published Date: Jan 10, 2025 (2 hours, 8 minutes ago) […]

BayMark Health Services Reports Data Breach, Exposing Patient Information

BayMark Health Services Reports Data Breach, Exposing Patient Information The BayMark Health Services, Inc. has reported a data breach to the California Attorney General, revealing that an unauthorized party had accessed sensitive files within the company’s computer network … Read more Published Date: Jan 10, 2025 (26 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-0311 – Orbit Fox by ThemeIsle Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-0311 Published : Jan. 10, 2025, 7:15 a.m. | 31 minutes ago Description : The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping on user supplied […]