CVE-2024-13338 – Clearfy Cache – WordPress CSRF

CVE ID : CVE-2024-13338 Published : April 12, 2025, 7:15 a.m. | 57 minutes ago Description : The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation […]

Hackers Actively Exploit Patched Fortinet FortiGate Devices to Gain Root Access Using Symbolic Link

Hackers Actively Exploit Patched Fortinet FortiGate Devices to Gain Root Access Using Symbolic Link Fortinet has uncovered a sophisticated post-exploitation technique used by a threat actor to maintain unauthorized access to FortiGate devices, even after initial vulnerabilities were patched. The dis … Read more Published Date: Apr 12, 2025 (2 hours, 17 minutes ago) Vulnerabilities has been […]

Threat Actors anchors Symlink trick on Fortinet Devices

Threat Actors anchors Symlink trick on Fortinet Devices The symlink trick is a post-exploitation technique used by attackers to maintain access to Fortinet devices even after initial vulnerabilities have been patched. This exploitation method leverages sym … Read more Published Date: Apr 12, 2025 (2 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-23010 […]

Active Directory Attack Kill Chain Checklist & Tools List- 2025

Active Directory Attack Kill Chain Checklist & Tools List- 2025 The “Active Directory Kill Chain Attack & Defense” concept is a structured approach to understanding the sequence of events or stages involved in an Active Directory (AD) attack and the corresponding … Read more Published Date: Apr 12, 2025 (1 hour, 34 minutes ago) Vulnerabilities has been […]

Hackers Exploiting Domain Controller to Deploy Ransomware Using RDP

Hackers Exploiting Domain Controller to Deploy Ransomware Using RDP Microsoft has recently uncovered a sharp rise in ransomware attacks exploiting domain controllers (DCs) through Remote Desktop Protocol (RDP), with the average attack costing organizations $9.36 milli … Read more Published Date: Apr 12, 2025 (2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2019-0708

CVE-2025-2871 – “QuadMenu Cross-Site Request Forgery (CSRF) Vulnerability”

CVE ID : CVE-2025-2871 Published : April 12, 2025, 4:15 a.m. | 1 hour, 57 minutes ago Description : The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the ajax_dismiss_notice() function. This makes […]

CVE-2025-2881 – “WordPress Developer Toolbar Sensitive Information Exposure”

CVE ID : CVE-2025-2881 Published : April 12, 2025, 3:15 a.m. | 27 minutes ago Description : The Developer Toolbar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained […]

CVE-2025-2841 – Cart66 Cloud WordPress Sensitive Information Exposure Vulnerability

CVE ID : CVE-2025-2841 Published : April 12, 2025, 3:15 a.m. | 27 minutes ago Description : The Cart66 Cloud plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.7 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained […]

CVE-2025-32726 – Visual Studio Code Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-32726 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 12, 2025 Action […]