CVE-2025-1702 – Ultimate Member – SQL Injection

CVE ID : CVE-2025-1702 Published : March 5, 2025, 12:15 p.m. | 2 hours, 2 minutes ago Description : The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘search’ parameter in all versions up to, and including, 2.10.0 due to […]

CVE-2024-12650 – Apache HTTP Server Memory Corruption Vulnerability

The following table lists the changes that have been made to the CVE-2024-12650 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 05, 2025 Action […]

CVE-2024-11153 – WordPress Restrict Content Plugin Sensitive Information Exposure

CVE ID : CVE-2024-11153 Published : March 5, 2025, 12:15 p.m. | 2 hours, 2 minutes ago Description : The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the WordPress core search […]

CISA Warns of Actively Exploited VMware Vulnerabilities, Urges Immediate Patching

CISA Warns of Actively Exploited VMware Vulnerabilities, Urges Immediate Patching The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on March 4, 2025, adding three critical VMware vulnerabilities to its Known Exploited Vulnerabilities (KEV) cata … Read more Published Date: Mar 05, 2025 (2 hours, 43 minutes ago) Vulnerabilities has been mentioned in this […]

Telegram EvilVideo Vulnerability Exploited to Execute Malicious Code on Victim Device

Telegram EvilVideo Vulnerability Exploited to Execute Malicious Code on Victim Device A critical evolution of the CVE-2024-7014 vulnerability, originally patched in July 2024, has resurfaced with updated tactics to bypass security measures. Dubbed Evilloader, this new exploit leverages … Read more Published Date: Mar 05, 2025 (1 hour, 58 minutes ago) Vulnerabilities has been mentioned in this […]

Use one Virtual Machine to own them all — active exploitation of ESXicape

Use one Virtual Machine to own them all — active exploitation of ESXicape Yesterday, VMware quietly released patches for three ESXi zero day vulnerabilities: CVE-2025–22224, CVE-2025–22225, CVE-2025–22226.The advisory:Although the advisory doesn’t explicitly say it, this is … Read more Published Date: Mar 05, 2025 (3 hours, 59 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2025-25015 – Kibana Prototype Pollution RCE

The following table lists the changes that have been made to the CVE-2025-25015 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics.

CVE-2025-1515 – WordPress Real Estate Manager LinkedIn Authentication Bypass

The following table lists the changes that have been made to the CVE-2025-1515 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics.

CVE-2025-0954 – WordPress WP Online Contract Unauthenticated RCE

The following table lists the changes that have been made to the CVE-2025-0954 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics.

CVE-2025-0956 – “WooCommerce Recover Abandoned Cart PHP Object Injection Vulnerability”

The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.3.0 via deserialization of untrusted input from the ‘raccookie_guest_email’ cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means […]