CVE-2025-1968 – Progress Software Corporation Sitefinity Session Replay Attack
The following table lists the changes that have been made to the CVE-2025-1968 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 09, 2025 Action […]
CVE-2023-33844 – IBM Security Verify Governance Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2023-33844 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 09, 2025 Action […]
Shopware Security Plugin Exposes Systems to SQL Injection Attacks
Shopware Security Plugin Exposes Systems to SQL Injection Attacks A plugin designed to patch security vulnerabilities in older versions of Shopware has itself been found vulnerable to SQL injection attacks. The flaw, discovered in Shopware Security Plugin 6 version … Read more Published Date: Apr 09, 2025 (2 hours, 16 minutes ago) Vulnerabilities has been mentioned in […]
WhatsApp vulnerability could be used to infect Windows users with malware (CVE-2025-30401)
WhatsApp vulnerability could be used to infect Windows users with malware (CVE-2025-30401) WhatsApp users are urged to update the Windows client app to plug a serious security vulnerability (CVE-2025-30401) that may allow attackers to trick users into running malicious code. Meta classifies … Read more Published Date: Apr 09, 2025 (54 minutes ago) Vulnerabilities has been […]
CISA KEV Catalog Update Part II – April 2025
CISA KEV Catalog Update Part II – April 2025 The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding several critical vulnerabilities that are actively being expl … Read more Published Date: Apr 09, 2025 (1 hour, 27 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-29824 CVE-2025-31161 CVE-2025-30406 […]
CVE-2025-31672 – Apache POI OOXML Duplicate Zip Entry Vulnerability
The following table lists the changes that have been made to the CVE-2025-31672 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Apr. 09, 2025 Action Type […]
CVE-2025-30677 – Apache Pulsar Apache Kafka Log Injection Vulnerability
Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This vulnerability can lead to unintended exposure of credentials in log files, potentially allowing attackers with access to these logs […]
CVE-2025-29189 – Flowise Postgres_VectorStores SQL Injection
The following table lists the changes that have been made to the CVE-2025-29189 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 09, 2025 Action […]
Windows Kerberos Vulnerability Let Attackers Bypass Security Feature & Access Credentials
Windows Kerberos Vulnerability Let Attackers Bypass Security Feature & Access Credentials Microsoft has released a patch for a critical Windows Kerberos vulnerability (CVE-2025-29809) that allows attackers to bypass security features and potentially access sensitive authentication credenti … Read more Published Date: Apr 09, 2025 (1 hour, 40 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-29809
CISA Warns of Microsoft Windows CLFS Vulnerability Exploited in Wild
CISA Warns of Microsoft Windows CLFS Vulnerability Exploited in Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft Windows vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The flaw in the Windows Comm … Read more Published Date: Apr 09, 2025 (1 hour, 43 minutes ago) Vulnerabilities has been mentioned in this […]