CVE-2025-0682 – ThemeREX Addons WordPress Local File Inclusion Vulnerability
CVE ID : CVE-2025-0682 Published : Jan. 25, 2025, 6:15 a.m. | 28 minutes ago Description : The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the ‘trx_sc_reviews’ shortcode ‘type’ attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to […]
CVE-2024-13721 – Plethora Plugins Tabs + Accordions WordPress Stored Cross-Site Scripting
CVE ID : CVE-2024-13721 Published : Jan. 25, 2025, 6:15 a.m. | 28 minutes ago Description : The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the anchor parameter in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2025-0411 – 7-Zip Mark-of-the-Web Bypass RCE Vulnerability
The following table lists the changes that have been made to the CVE-2025-0411 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 25, 2025 Action […]
CVE-2024-13709 – WordPress Linear CSRF Weakness
CVE ID : CVE-2024-13709 Published : Jan. 25, 2025, 4:15 a.m. | 29 minutes ago Description : The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on the ‘linear-debug’. This makes it possible for unauthenticated attackers to […]
CVE-2025-0357 – WordPress WPBookit Plugin Arbitrary File Upload Vulnerability
CVE ID : CVE-2025-0357 Published : Jan. 25, 2025, 2:15 a.m. | 2 hours, 28 minutes ago Description : The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the ‘WPB_Profile_controller::handle_image_upload’ function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary […]
PANdora Box Vulnerabilities in PaloAlto Firewalls
PANdora Box Vulnerabilities in PaloAlto Firewalls Overview of PANdora’s BoxPANdora’s Box is a term used to describe a series of critical vulnerabilities identified in various models of Palo Alto Networks’ firewalls. These vulnerabilities have signifi … Read more Published Date: Jan 25, 2025 (3 hours, 18 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-0314 CVE-2025-23006 […]
CVE-2025-24361 – Nuxt Cross-Site Scripting with Source Leak
The following table lists the changes that have been made to the CVE-2025-24361 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 25, 2025 Action […]
CVE-2025-24360 – Nuxt Cross-Origin Request Exposure Vulnerability
The following table lists the changes that have been made to the CVE-2025-24360 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 25, 2025 Action […]