CVE-2025-32925 – FantasticPlugins SUMO Reward Points PHP Remote File Inclusion

The following table lists the changes that have been made to the CVE-2025-32925 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]

CVE-2025-32924 – Roninwp Revy SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-32924 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]

CVE-2025-47934 – OpenPGP.js Signature Verification Spoofing

OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data that was not actually signed. This flaw allows signature verifications […]

CVE-2025-47577 – TemplateInvaders TI WooCommerce Wishlist Unrestricted File Upload Remote Code Execution

The following table lists the changes that have been made to the CVE-2025-47577 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]

CVE-2025-47284 – Gardener Gardenlet Privilege Escalation Vulnerability

Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters […]

CVE-2025-47283 – Gardener gardenlet Administrative Privilege Escalation Vulnerability

Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE […]

CVE-2025-43839 – Shanebp BP Messages Tool Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-43839 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]

CVE-2025-39451 – Crocoblock JetBlocks For Elementor Missing Authorization Vulnerability

The following table lists the changes that have been made to the CVE-2025-39451 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]

CVE-2025-39449 – Crocoblock JetWooBuilder Missing Authorization Vulnerability

The following table lists the changes that have been made to the CVE-2025-39449 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]