CVE-2025-4825 – TOTOLINK A702R/A3002R/A3002RU HTTP POST Request Handler Buffer Overflow
The following table lists the changes that have been made to the CVE-2025-4825 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 17, 2025 Action […]
CVE-2025-4824 – TOTOLINK A702R, A3002R, A3002RU HTTP POST Request Handler Buffer Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-4824 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 17, 2025 Action […]
CVE-2025-4823 – TOTOLINK HTTP POST Request Handler Buffer Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-4823 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 17, 2025 Action […]
CVE-2025-4610 – WordPress WP-Members Membership Plugin Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-4610 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 17, 2025 Action […]
CVE-2025-4819 – Y_Project RuoYi Remote Improper Authorization Vulnerability
The following table lists the changes that have been made to the CVE-2025-4819 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 17, 2025 Action […]
CVE-2025-4391 – WordPress Echo RSS Feed Post Generator Arbitrary File Upload Vulnerability
CVE ID : CVE-2025-4391 Published : May 17, 2025, 6:15 a.m. | 24 minutes ago Description : The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated […]
CVE-2025-4389 – “WordPress Crawlomatic Multipage Scraper Plugin Arbitrary File Upload Vulnerability”
CVE ID : CVE-2025-4389 Published : May 17, 2025, 6:15 a.m. | 24 minutes ago Description : The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for unauthenticated […]
CVE-2025-4190 – WordPress CSV Mass Importer File Upload Privilege Escalation Vulnerability
CVE ID : CVE-2025-4190 Published : May 17, 2025, 6:15 a.m. | 24 minutes ago Description : The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in […]
CVE-2025-3812 – WordPress WPBot Pro File Deletion Vulnerability
CVE ID : CVE-2025-3812 Published : May 17, 2025, 6:15 a.m. | 24 minutes ago Description : The WPBot Pro WordPress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the qcld_openai_delete_training_file() function in all versions up to, and including, 13.6.2. This makes it possible for authenticated attackers, […]
CVE-2025-4818 – SourceCodester Doctor’s Appointment System SQL Injection
The following table lists the changes that have been made to the CVE-2025-4818 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 17, 2025 Action […]