CVE-2025-3921 – PeproDev Ultimate Profile Solutions WordPress Unauthenticated Data Modification Vulnerability

The following table lists the changes that have been made to the CVE-2025-3921 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-3860 – CarDealerPress for WordPress Stored Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-3860 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-3853 – WordPress WPshop E-Commerce Plugin Insecure Direct Object Reference Vulnerability

The following table lists the changes that have been made to the CVE-2025-3853 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-3852 – WordPress WPshop E-Commerce Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-3852 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-3851 – WordPress SmartPay Insecure Direct Object Reference Vulnerability

The following table lists the changes that have been made to the CVE-2025-3851 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-3844 – PeproDev Ultimate Profile Solutions WordPress Authentication Bypass

The following table lists the changes that have been made to the CVE-2025-3844 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CVE-2025-2821 – WordPress Search Exclude Plugin Unauthenticated Data Modification

The following table lists the changes that have been made to the CVE-2025-2821 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 07, 2025 Action […]

CISA Adds CVE-2025-27363 to KEV Catalog

CISA Adds CVE-2025-27363 to KEV Catalog The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-27363, a critical out-of-bounds write vulnerability in FreeType, to its Known Exploited Vulnerabilities (KEV) Catalog due … Read more Published Date: May 07, 2025 (50 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-27363

CVE-2025-3218 – IBM i Netserver Authentication Bypass

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.

CVE-2025-25014 (CVSS 9.1): Prototype Pollution in Kibana Opens Door to Code Execution

CVE-2025-25014 (CVSS 9.1): Prototype Pollution in Kibana Opens Door to Code Execution Elastic has issued a critical security advisory for Kibana, warning users of a vulnerability tracked as CVE-2025-25014. Scoring a CVSS of 9.1, this flaw stems from a prototype pollution vulnerability … Read more Published Date: May 07, 2025 (2 hours, 22 minutes ago) Vulnerabilities has […]