CVE-2025-32648 – Projectopia Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-32648 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]
CVE-2025-32647 – PickPlugins Question Answer Object Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-32647 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]
CVE-2025-32636 – Oracle Local Magic SQL Injection
The following table lists the changes that have been made to the CVE-2025-32636 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]
Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates
Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates The China-linked threat actor known as Mustang Panda has been attributed to a cyber attack targeting an unspecified organization in Myanmar with previously unreported tooling, highlighting continued e … Read more Published Date: Apr 17, 2025 (57 minutes ago) Vulnerabilities has been mentioned in this […]
Hackers Weaponize MMC Script to Deploy MysterySnail RAT Malware
Hackers Weaponize MMC Script to Deploy MysterySnail RAT Malware A sophisticated cyberespionage campaign leveraging malicious Microsoft Management Console (MMC) scripts to deploy the stealthy MysterySnail remote access trojan (RAT). First identified in 2021 during … Read more Published Date: Apr 17, 2025 (3 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2021-40449
CVE-2025-29015 – Code Astro Internet Banking System Cross Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2025-29015 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]
CVE-2025-3760 – Liferay Portal Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix […]
Windows NTLM vulnerability exploited in multiple attack campaigns (CVE-2025-24054)
Windows NTLM vulnerability exploited in multiple attack campaigns (CVE-2025-24054) CVE-2025-24054, a Windows NTLM hash disclosure vulnerability that Microsoft has issued patches for last month, has been leveraged by threat actors in campaigns targeting government and private institu … Read more Published Date: Apr 17, 2025 (1 hour, 50 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-3487 – Forminator Forms – WordPress Stored Cross-Site Scripting
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject […]
CVE-2025-3479 – Forminator Forms – WordPress Stripe Payment Intent Order Replay Vulnerability
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the ‘handle_stripe_single’ function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for […]