Fortinet waarschuwt voor ‘read-only aanval’ op FortiGate-firewalls
Fortinet waarschuwt voor ‘read-only aanval’ op FortiGate-firewalls Fortinet waarschuwt klanten voor een nieuwe techniek waarvan aanvallers gebruikmaken en ervoor zorgt dat ze read-only toegang tot FortiGate-firewalls behouden. Volgens het bedrijf maken de aanvallers … Read more Published Date: Apr 11, 2025 (4 hours, 15 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-21762 CVE-2023-27997 CVE-2022-42475
CVE-2025-3439 – Everest Forms WordPress PHP Object Injection Vulnerability
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the ‘field_value’ parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known […]
CVE-2025-3421 – Everest Forms – WordPress Reflected Cross-Site Scripting Vulnerability
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘form_id’ parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web […]
CVE-2024-13861 – Taegis Endpoint Agent Debian Package Code Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-13861 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 11, 2025 Action […]
CVE-2025-3422 – Everest Forms WordPress Plugin Arbitrary Shortcode Execution Vulnerability
The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. […]
11 Bugs Found in Perplexity AI’s Chatbot Android App
11 Bugs Found in Perplexity AI’s Chatbot Android App Source: Sipa USA via Alamy Stock PhotoResearchers have identified nearly a dozen security issues in the research-oriented AI chatbot Perplexity.Perplexity was released one week after ChatGPT, right as … Read more Published Date: Apr 11, 2025 (2 hours, 40 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-2541 – WordPress Project Manager SVG Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-2541 Published : April 11, 2025, 12:15 p.m. | 29 minutes ago Description : The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]
CVE-2025-2575 – WordPress Z Companion Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-2575 Published : April 11, 2025, 12:15 p.m. | 29 minutes ago Description : The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]
CVE-2024-52280 – SUSE Rancher Information Disclosure Vulnerability
The following table lists the changes that have been made to the CVE-2024-52280 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 11, 2025 Action […]
WordPress Plugin Vulnerability Exposes Sites to Critical File Inclusion Attacks
WordPress Plugin Vulnerability Exposes Sites to Critical File Inclusion Attacks A severe security vulnerability has been discovered in the popular InstaWP Connect WordPress plugin, potentially exposing thousands of websites to remote attacks. Security researchers at Wordfence ide … Read more Published Date: Apr 11, 2025 (3 hours, 32 minutes ago) Vulnerabilities has been mentioned in this article. […]