CVE-2025-22273 – CyberArk Endpoint Privilege Manager Unbounded Brute Force Password Change
The following table lists the changes that have been made to the CVE-2025-22273 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 28, 2025 Action […]
CVE-2025-22272 – CyberArk Endpoint Privilege Manager Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2025-22272 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 28, 2025 Action […]
CVE-2025-22271 – CyberArk Endpoint Privilege Manager IP Address Spoofing Vulnerability
The following table lists the changes that have been made to the CVE-2025-22271 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 28, 2025 Action […]
CVE-2025-22270 – CyberArk Endpoint Privilege Manager HTML Injection Vulnerability
An attacker with access to the Administration panel, specifically the “Role Management” tab, can inject code by adding a new role in the “name” field. It should be noted, however, that the risk of exploiting vulnerability is reduced due to the required additional error that allows bypassing the Content-Security-Policy policy, which mitigates JS code execution […]
CVE-2025-1300 – CodeChecker Open Redirect Vulnerability
The following table lists the changes that have been made to the CVE-2025-1300 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 85b1779b-6ecd-4f52-bcc5-73eac4659dcf Feb. 28, 2025 Action […]
CVE-2025-1319 – WordPress Site Mailer Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1319 Published : Feb. 28, 2025, 1:15 p.m. | 59 minutes ago Description : The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes […]
PolarEdge Botnet Campaign
PolarEdge Botnet Campaign PolarEdge Botnet has emerged as a significant threat in the cybersecurity landscape, exploiting vulnerabilities in edge devices from multiple manufacturers, including Cisco, ASUS, QNAP, and Synology. … Read more Published Date: Feb 28, 2025 (1 hour, 45 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2023-20118
CISA Appoints Karen Evans as New Cybersecurity Executive Assistant Director
CISA Appoints Karen Evans as New Cybersecurity Executive Assistant Director Karen Evans has been appointed as the new Executive Assistant Director (EAD) for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA). In this new role, Evans brings an extensi … Read more Published Date: Feb 28, 2025 (1 hour, 49 minutes ago) Vulnerabilities has been mentioned […]
Vulnerabilities in CyberArk Endpoint Privilege Manager software
Vulnerabilities in CyberArk Endpoint Privilege Manager software CVE ID CVE-2025-22270 Publication date 28 February 2025 Vendor CyberArk Product Endpoint Privilege Manager Vulnerable versions 24.7.1 Vulnerability type (CWE) Improper Neutralization of Input During W … Read more Published Date: Feb 28, 2025 (2 hours, 14 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22274 CVE-2025-22273 CVE-2025-22272 CVE-2025-22271 […]
PingAM Java Agent Vulnerability Let Attackers Gain Unauthorized Access
PingAM Java Agent Vulnerability Let Attackers Gain Unauthorized Access Ping Identity has issued an urgent security advisory for its PingAM Java Agent, revealing a critical severity vulnerability (CVE-2025-20059) that enables attackers to bypass policy enforcement mechani … Read more Published Date: Feb 28, 2025 (2 hours, 36 minutes ago) Vulnerabilities has been mentioned in this article.