CVE-2025-3861 – WordPress Prevent Direct Access Unauthorized Access Vulnerability
The following table lists the changes that have been made to the CVE-2025-3861 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]
CVE-2025-3511 – Mitsubishi Electric Corporation CC-Link IE TSN Denial of Service Remote Buffer Overflow
The following table lists the changes that have been made to the CVE-2025-3511 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]
CVE-2025-2580 – Bit Form WordPress Contact Form Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-2580 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]
CVE-2025-0671 – Icegram Express WordPress Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-0671 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]
SAP NetWeaver 0-day Vulnerability Exploited in the Wild to Deploy Webshells
SAP NetWeaver 0-day Vulnerability Exploited in the Wild to Deploy Webshells A wave of targeted cyberattacks has exposed a previously unknown vulnerability in SAP NetWeaver, allowing attackers to deploy malicious JSP webshells and gain unauthorized access to enterprise systems … Read more Published Date: Apr 25, 2025 (23 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2025-46599 – K3s Kubernetes Kubelet ReadWritePort Remote Authentication Bypass
The following table lists the changes that have been made to the CVE-2025-46599 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 25, 2025 Action […]
CVE-2025-3775 – ShopLentor WooCommerce Builder SSRF Vulnerability
CVE ID : CVE-2025-3775 Published : April 25, 2025, 5:15 a.m. | 42 minutes ago Description : The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. […]
CVE-2025-3752 – Able Player WordPress Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-3752 Published : April 25, 2025, 5:15 a.m. | 42 minutes ago Description : The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it […]
Lazarus APT Attacking Organizations by Exploiting One-Day vulnerabilities
Lazarus APT Attacking Organizations by Exploiting One-Day vulnerabilities Cybersecurity experts have identified a sophisticated campaign by the North Korean state-sponsored Lazarus APT group targeting critical infrastructure and financial organizations worldwide. The threat … Read more Published Date: Apr 25, 2025 (1 hour, 19 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2025-46595 – Backdrop CMS Flag Module Cross-Site Scripting Vulnerability
An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn’t verify flag links before performing the flag action, or verify that the response returned was provided by the flag […]