CVE-2025-3058 – Xelion Webchat WordPress Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-3058 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]

CVE-2025-2579 – Lottie Player WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2579 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]

CVE-2025-2543 – WordPress Advanced Accordion Gutenberg Block Stored Cross-Site Scripting

CVE ID : CVE-2025-2543 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible […]

CVE-2025-1284 – Woocommerce Automatic Order Printing Insecure Direct Object Reference

CVE ID : CVE-2025-1284 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing […]

CVE-2024-13307 – Reales WP Real Estate WordPress Theme Unauthenticated File Deletion and Authorization Bypass Vulnerability

CVE ID : CVE-2024-13307 Published : April 24, 2025, 9:15 a.m. | 1 hour, 51 minutes ago Description : The Reales WP – Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘reales_delete_file’, ‘reales_delete_file_plans’, ‘reales_add_to_favourites’, and ‘reales_remove_from_favourites’ functions in all versions up […]

SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances

SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances SonicWall has disclosed a critical security vulnerability in its SSLVPN service that allows unauthenticated remote attackers to crash affected firewall appliances, potentially causing significant disr … Read more Published Date: Apr 24, 2025 (2 hours, 8 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-32818

CVE-2025-1908 – GitLab Information Disclosure and Session Hijacking Vulnerability

The following table lists the changes that have been made to the CVE-2025-1908 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]

CVE-2025-0639 – GitLab CE/EE Service Availability Denial of Service

The following table lists the changes that have been made to the CVE-2025-0639 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]

CVE-2024-12244 – GitLab EE Information Disclosure

The following table lists the changes that have been made to the CVE-2024-12244 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]

CVE-2025-41423 – Mattermost Playbooks API Permission Validation Bypass

The following table lists the changes that have been made to the CVE-2025-41423 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 24, 2025 Action […]