CVE-2025-2168 – Elementor Store Kit CSRF

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce validation on the dismiss() function. This makes it possible for unauthenticated […]

CVE-2025-1305 – NewsBlogger WordPress CSRF Remote Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-1305 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 01, 2025 Action […]

CVE-2025-1304 – NewsBlogger for WordPress Arbitrary File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2025-1304 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 01, 2025 Action […]

CVE-2025-4147 – Netgear EX6200 Remote Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-4147 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 01, 2025 Action […]

CVE-2025-4146 – Netgear EX6200 Remote Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2025-4146 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 01, 2025 Action […]

SonicWall Confirms Active Exploitation of SMA 100 Vulnerabilities – Urges Immediate Patching

SonicWall Confirms Active Exploitation of SMA 100 Vulnerabilities – Urges Immediate Patching On April 29, 2025, SonicWall issued an urgent update to two previously disclosed vulnerabilities affecting its SMA 100 Series appliances, confirming that both flaws are now actively being exploited in … Read more Published Date: May 01, 2025 (1 hour, 2 minutes ago) Vulnerabilities has […]

CVE-2025-4144 – Cloudflare Workers-Oauth-Provider PKCE Bypass

The following table lists the changes that have been made to the CVE-2025-4144 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 01, 2025 Action […]

CVE-2025-4143 – Cloudflare Workers-OAuth-Provider OAuth Redirect URI Validation Bypass

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in:  https://github.com/cloudflare/workers-oauth-provider/pull/26 https://github.com/cloudflare/workers-oauth-provider/pull/26 Impact: Under certain circumstances (see below), if a victim had previously authorized with a server built on workers-oath-provider, and […]

CVE-2025-4145 – Netgear EX6200 Remote Buffer Overflow

The following table lists the changes that have been made to the CVE-2025-4145 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 01, 2025 Action […]