CISA adds Ivanti Connect Secure to KEV Catalog

CISA adds Ivanti Connect Secure to KEV Catalog The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Ivanti Connect Secure to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, identi … Read more Published Date: Apr 05, 2025 (1 hour, 56 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-22457

CVE-2025-2544 – WordPress AI Content Pipelines Stored Cross-Site Scripting

CVE ID : CVE-2025-2544 Published : April 5, 2025, 2:15 a.m. | 1 hour, 29 minutes ago Description : The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for […]

CVE-2025-0810 – WordPress Read More & Accordion CSRF

CVE ID : CVE-2025-0810 Published : April 5, 2025, 2:15 a.m. | 1 hour, 29 minutes ago Description : The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.5. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it […]

CVE-2025-2933 – “WordPress Email Notifications for Updates Unauthenticated Privilege Escalation”

The following table lists the changes that have been made to the CVE-2025-2933 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]

CVE-2024-13604 – KB Support WordPress Sensitive Information Exposure Vulnerability

CVE ID : CVE-2024-13604 Published : April 5, 2025, 2:15 a.m. | 1 hour, 29 minutes ago Description : The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the ‘kbs’ directory. This makes it possible […]

CVE-2025-1500 – IBM Maximo Application Suite File Upload Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-1500 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 05, 2025 Action […]

50K+ WordPress Sites Exposed: Admin Takeover via Uncanny Automator

50K+ WordPress Sites Exposed: Admin Takeover via Uncanny Automator A vulnerability has surfaced in the popular WordPress plugin, Uncanny Automator, leaving over 50,000 websites potentially exposed to complete compromise. Tracked as CVE-2025-2075, this critical flaw, … Read more Published Date: Apr 05, 2025 (1 hour, 18 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-2075 CVE-2024-53868 […]

CVE-2025-2889 – WordPress Link Library Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2889 Published : April 5, 2025, 12:15 a.m. | 1 hour, 26 minutes ago Description : The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for […]

Windows 11 Hotpatch: Enterprise Only, Reboot-Free Updates

Windows 11 Hotpatch: Enterprise Only, Reboot-Free Updates Microsoft previously introduced Hotpatching updates for Windows 11 Enterprise users—a mechanism that allows critical security patches to take effect immediately without requiring a system reboot. This … Read more Published Date: Apr 05, 2025 (1 hour, 36 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-49138 CVE-2024-38063