CVE-2025-41395 – Mattermost Denial of Service (DoS) Vulnerability
The following table lists the changes that have been made to the CVE-2025-41395 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-35965 – Mattermost Denial-of-Service DoS Vulnerability
The following table lists the changes that have been made to the CVE-2025-35965 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-32730 – i-PRO Co., Ltd. Surveillance Cameras and Recorders Cryptographic Key Hard-Coded Authentication Bypass
The following table lists the changes that have been made to the CVE-2025-32730 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]
CVE-2025-3761 – My Tickets – WordPress Privilege Escalation Vulnerability
CVE ID : CVE-2025-3761 Published : April 24, 2025, 7:15 a.m. | 1 hour, 27 minutes ago Description : The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to […]
1000+ Unique IPs Attacking Ivanti Connect Secure Systems to Exploit Vulnerabilities
1000+ Unique IPs Attacking Ivanti Connect Secure Systems to Exploit Vulnerabilities A significant increase in suspicious scanning activity targeting Ivanti Connect Secure (ICS) and Ivanti Pulse Secure (IPS) VPN systems, signaling a potential coordinated reconnaissance effort by threa … Read more Published Date: Apr 24, 2025 (2 hours, 29 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2025-2558 – “WordPress Theme-Wound LFI Vulnerability”
CVE ID : CVE-2025-2558 Published : April 24, 2025, 6:15 a.m. | 21 minutes ago Description : The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server Severity: 0.0 | NA Visit […]
CVE-2025-1453 – WordPress Category Posts Widget Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1453 Published : April 24, 2025, 6:15 a.m. | 21 minutes ago Description : The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed […]
A new era of cyber threats is approaching for the energy sector
A new era of cyber threats is approaching for the energy sector Cyber threats targeting the energy sector come in many forms, including state-sponsored actors seeking to disrupt national infrastructure, cybercriminals motivated by profit, and insiders intentionall … Read more Published Date: Apr 24, 2025 (1 hour, 42 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-3435 – Mang Board WP Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-3435 Published : April 24, 2025, 4:15 a.m. | 21 minutes ago Description : The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2025-1021 impacts Synology DiskStation Manager
CVE-2025-1021 impacts Synology DiskStation Manager CVE-2025-1021 is a critical vulnerability affecting Synology DiskStation Manager (DSM), specifically its Network File System (NFS) service. This flaw allows unauthenticated remote attackers to read ar … Read more Published Date: Apr 24, 2025 (3 hours, 27 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-1021 CVE-2025-1732 CVE-2025-1731 CVE-2025-32433 CVE-2025-24054