CVE-2025-32925 – FantasticPlugins SUMO Reward Points PHP Remote File Inclusion
The following table lists the changes that have been made to the CVE-2025-32925 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]
CVE-2025-32924 – Roninwp Revy SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-32924 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]
CVE-2025-47934 – OpenPGP.js Signature Verification Spoofing
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data that was not actually signed. This flaw allows signature verifications […]
CVE-2025-47581 – Elbisnero WordPress Events Calendar Registration & Tickets Object Injection Vulnerability
CVE ID : CVE-2025-47581 Published : May 19, 2025, 7:15 p.m. | 39 minutes ago Description : Deserialization of Untrusted Data vulnerability in Elbisnero WordPress Events Calendar Registration & Tickets allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0. Severity: 9.8 | CRITICAL Visit the link for more details, such […]
CVE-2025-47577 – TemplateInvaders TI WooCommerce Wishlist Unrestricted File Upload Remote Code Execution
The following table lists the changes that have been made to the CVE-2025-47577 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]
CVE-2025-47284 – Gardener Gardenlet Privilege Escalation Vulnerability
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters […]
CVE-2025-47283 – Gardener gardenlet Administrative Privilege Escalation Vulnerability
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE […]
CVE-2025-43839 – Shanebp BP Messages Tool Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-43839 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]
CVE-2025-39451 – Crocoblock JetBlocks For Elementor Missing Authorization Vulnerability
The following table lists the changes that have been made to the CVE-2025-39451 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]
CVE-2025-39449 – Crocoblock JetWooBuilder Missing Authorization Vulnerability
The following table lists the changes that have been made to the CVE-2025-39449 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 19, 2025 Action […]