CVE-2025-30235 – Shearwater SecurEnvoy SecurAccess Account Brute Force
The following table lists the changes that have been made to the CVE-2025-30235 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-1232 – “WordPress Site Reviews Stored XSS Vulnerability”
CVE ID : CVE-2025-1232 Published : March 19, 2025, 6:15 a.m. | 1 hour, 4 minutes ago Description : The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks Severity: 0.0 | NA Visit the link for more details, […]
CVE-2024-50631 – Synology Drive Server SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-50631 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2024-50630 – Synology Drive Server Authentication Bypass
The following table lists the changes that have been made to the CVE-2024-50630 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2024-50629 – Synology BeeStation Manager/DiskStation Manager/Unified Controller File Disclosure
The following table lists the changes that have been made to the CVE-2024-50629 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2024-12922 – Altair WordPress Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2024-12922 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2025-2290 – LifterLMS WordPress Plugin Unauthenticated Post Trashing Vulnerability
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated attackers to change status to “Trash” […]
CVE-2025-30234 – SmartOS SSH Key Disclosure
The following table lists the changes that have been made to the CVE-2025-30234 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]
CVE-2024-12295 – BoomBox Theme Extensions WordPress Privilege Escalation Vulnerability
The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user’s identity prior to updating their password through the ‘boombox_ajax_reset_password’ function. This makes it possible for authenticated attackers, with subscriber-level privileges and […]
CVE-2024-11131 – Synology Camera Firmware Out-of-Bounds Read Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2024-11131 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 19, 2025 Action […]