CVE-2024-13325 – Glossy WordPress Reflected Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-13325 Published : Feb. 4, 2025, 6:15 a.m. | 35 minutes ago Description : The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin Severity: 0.0 […]

CVE-2025-24982 – WinterLock CSRF Delete

The following table lists the changes that have been made to the CVE-2025-24982 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]

Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score

Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score Vulnerability / Cloud Security Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to e … Read more Published Date: Feb 04, 2025 (3 hours, 7 minutes ago) Vulnerabilities has […]

Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104

Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104 Vulnerability / Mobile Security Google has shipped patches to address 47 security flaws in its Android operating system, including one it said has come under active exploitation in the wild. The vulne … Read more Published Date: Feb 04, 2025 (3 hours, 24 minutes ago) Vulnerabilities has […]

CVE-2025-22475 – Dell PowerProtect DD Cryptographic Primitive Information Tampering Vulnerability

The following table lists the changes that have been made to the CVE-2025-22475 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]

CVE-2025-1003 – HP Anyware Agent for Linux Privilege Escalation Authentication Bypass

The following table lists the changes that have been made to the CVE-2025-1003 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 04, 2025 Action […]

CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks

CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks Summary In September, 2024 the Zero Day Initiative (ZDI) Threat Hunting team identified the exploitation of a 7-Zip zero-day vulnerability used in a SmokeLoader malware campaign targeting Ukrainian en … Read more Published Date: Feb 04, 2025 (10 hours, 21 minutes ago) Vulnerabilities has been mentioned in […]