CVE-2025-3297 – SourceCodester Online Eyewear Shop Cross Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-3297 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]
CVE-2025-3296 – SourceCodester Online Eyewear Shop SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-3296 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]
“IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control
“IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control A recently discovered set of vulnerabilities, dubbed “IngressNightmare,” found in Ingress NGINX Controller, exposing clusters to unauthenticated remote code execution (RCE). Kubernetes dominates conta … Read more Published Date: Apr 05, 2025 (2 hours, 28 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-2941 – WooCommerce Drag and Drop Multiple File Upload Remote File Moving Vulnerability
CVE ID : CVE-2025-2941 Published : April 5, 2025, 7:15 a.m. | 36 minutes ago Description : The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it […]
CVE-2025-2789 – MultiVendorX Unauthenticated Table Rates Deletion Vulnerability
CVE ID : CVE-2025-2789 Published : April 5, 2025, 6:15 a.m. | 1 hour, 36 minutes ago Description : The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row […]
CVE-2025-1233 – Lafka Plugin for WordPress Unauthorized Theme Option Update Vulnerability
CVE ID : CVE-2025-1233 Published : April 5, 2025, 6:15 a.m. | 1 hour, 36 minutes ago Description : The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ‘lafka_options_upload’ AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level […]
CVE-2025-0839 – ZoomSounds Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-0839 Published : April 5, 2025, 6:15 a.m. | 1 hour, 36 minutes ago Description : The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated […]
CVE-2024-13776 – “ZoomSounds WordPress Wave Audio Player with Playlist Unauthorized Data Modification Vulnerability”
The following table lists the changes that have been made to the CVE-2024-13776 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]
CVE-2025-32352 – ZendTo PHP Authentication Type Confusion Vulnerability
The following table lists the changes that have been made to the CVE-2025-32352 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]
CVE-2021-47667 – ZendTo OS Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2021-47667 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]