CVE-2025-3113 – Continuous Compliance Internal Database Exposure

The following table lists the changes that have been made to the CVE-2025-3113 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]

CVE-2025-2903 – Google Cloud Platform OS Login SSH Authentication Bypass

The following table lists the changes that have been made to the CVE-2025-2903 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]

Synology NAS: Third-Party Drives Restricted in 2025 Plus Series

Synology NAS: Third-Party Drives Restricted in 2025 Plus Series Synology NAS servers have long been favored by both enthusiasts and enterprises alike. The wide array of features offered by Synology enables users to back up data, share files, run various applicatio … Read more Published Date: Apr 17, 2025 (2 hours, 56 minutes ago) Vulnerabilities has been […]

CVE-2025-3295 – WordPress WP Editor Arbitrary File Read Vulnerability

CVE ID : CVE-2025-3295 Published : April 17, 2025, 6:15 a.m. | 1 hour, 28 minutes ago Description : The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the […]

CVE-2025-3294 – WordPress WP Editor Remote File Write Vulnerability

CVE ID : CVE-2025-3294 Published : April 17, 2025, 6:15 a.m. | 1 hour, 28 minutes ago Description : The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, […]

CVE-2025-1525 – The Ultimate Dashboard WordPress Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-1525 Published : April 17, 2025, 6:15 a.m. | 1 hour, 28 minutes ago Description : The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed […]

CVE-2025-1524 – The Ultimate Dashboard WordPress Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-1524 Published : April 17, 2025, 6:15 a.m. | 1 hour, 28 minutes ago Description : The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed […]

CVE-2024-13925 – Klarna Checkout for WooCommerce File Log Flood Vulnerability

CVE ID : CVE-2024-13925 Published : April 17, 2025, 6:15 a.m. | 1 hour, 28 minutes ago Description : The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This […]

CVE-2024-11924 – WordPress Icegram Express Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-11924 Published : April 17, 2025, 6:15 a.m. | 1 hour, 28 minutes ago Description : The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when […]