CVE-2024-11142 – Gosoft Software Proticaret E-Commerce CSRF Vulnerability

The following table lists the changes that have been made to the CVE-2024-11142 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 02, 2025 Action […]

NVIDIA TensorRT-LLM High-Severity Vulnerability Let Attackers Remote Code

NVIDIA TensorRT-LLM High-Severity Vulnerability Let Attackers Remote Code NVIDIA has disclosed and patched a high-severity vulnerability in its TensorRT-LLM framework that could allow attackers with local access to execute malicious code, tamper with data, and potentially c … Read more Published Date: May 02, 2025 (3 hours, 35 minutes ago) Vulnerabilities has been mentioned in this article. […]

Apple Revises U.S. App Store Rules After Court Ruling in Epic Games Case

Apple Revises U.S. App Store Rules After Court Ruling in Epic Games Case Following a court ruling that found Apple had willfully violated antitrust regulations—and the subsequent approval of Epic Games’ motion to enforce an injunction—Apple has now amended its App Store gu … Read more Published Date: May 02, 2025 (1 hour, 57 minutes ago) Vulnerabilities […]

Redis Reintroduces Open-Source AGPL Alongside SSPL Licensing

Redis Reintroduces Open-Source AGPL Alongside SSPL Licensing In March 2024, the widely adopted database caching solution Redis announced its transition to the Server Side Public License (SSPL)—a license that, while offering source code access, is not recognized … Read more Published Date: May 02, 2025 (2 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2024-13860 – Buddyboss WordPress Stored Cross-Site Scripting

CVE ID : CVE-2024-13860 Published : May 2, 2025, 7:15 a.m. | 17 minutes ago Description : The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]

CVE-2024-13859 – Buddyboss WordPress Stored Cross-Site Scripting

CVE ID : CVE-2024-13859 Published : May 2, 2025, 7:15 a.m. | 17 minutes ago Description : The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]

CVE-2024-13858 – Buddyboss Platform Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-13858 Published : May 2, 2025, 7:15 a.m. | 17 minutes ago Description : The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]

CISA Warns of SonicWall SMA100 OS Command Injection Vulnerability Exploited in Wild

CISA Warns of SonicWall SMA100 OS Command Injection Vulnerability Exploited in Wild CISA has added the SonicWall SMA100 OS Command Injection Vulnerability, tracked as CVE-2023-44221, to its Known Exploited Vulnerabilities (KEV) catalog. According to CISA’s May 1, 2025 advisory, this … Read more Published Date: May 02, 2025 (2 hours, 51 minutes ago) Vulnerabilities has been mentioned […]

CISA Warns of Apache HTTP Server Escape Vulnerability Exploited in the Wild

CISA Warns of Apache HTTP Server Escape Vulnerability Exploited in the Wild The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-38475, a critical vulnerability affecting Apache HTTP Server, to its Known Exploited Vulnerabilities (KEV) catalog. This … Read more Published Date: May 02, 2025 (3 hours, 6 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-47201 – Intrexx Portal Server Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2025-47201 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 02, 2025 Action […]