CVE-2025-46535 – AlphaEfficiencyTeam Custom Login and Registration Missing Authorization Vulnerability

The following table lists the changes that have been made to the CVE-2025-46535 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]

CVE-2025-46616 – Quantum StorNext Web GUI API RCE

The following table lists the changes that have been made to the CVE-2025-46616 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]

CVE-2025-46617 – Quantum StorNext Web GUI API Unauthorized Configuration Access and Modification

The following table lists the changes that have been made to the CVE-2025-46617 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]

CVE-2025-3868 – WordPress Custom Admin-Bar Favorites Reflected Cross-Site Scripting

CVE ID : CVE-2025-3868 Published : April 25, 2025, 7:15 a.m. | 42 minutes ago Description : The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘menuObject’ parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated […]

CVE-2025-3867 – WordPress Ajax Comment Form CST CSRF

CVE ID : CVE-2025-3867 Published : April 25, 2025, 7:15 a.m. | 42 minutes ago Description : The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the ‘acform_cst_settings’ page. This makes it possible […]

CVE-2025-3866 – Google Plus One Social Share Button CSRF Vulnerability

CVE ID : CVE-2025-3866 Published : April 25, 2025, 7:15 a.m. | 42 minutes ago Description : The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. […]

CVE-2025-3743 – WooCommerce Upsell Funnel Builder Order Manipulation Vulnerability

CVE ID : CVE-2025-3743 Published : April 25, 2025, 7:15 a.m. | 42 minutes ago Description : The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated […]

CVE-2025-2238 – Vikinger WordPress Privilege Escalation Vulnerability

CVE ID : CVE-2025-2238 Published : April 25, 2025, 7:15 a.m. | 42 minutes ago Description : The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the ‘vikinger_user_meta_update_ajax’ function. This makes it possible for authenticated attackers, with Subscriber-level access and […]

CVE-2025-46613 – OpenPLC Server Memory Corruption

The following table lists the changes that have been made to the CVE-2025-46613 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]

CVE-2025-3923 – WordPress Prevent Direct Access – Sensitive Information Exposure

The following table lists the changes that have been made to the CVE-2025-3923 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]