CVE-2025-41230 – VMware Cloud Foundation SSL/TLS Information Disclosure
The following table lists the changes that have been made to the CVE-2025-41230 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]
CVE-2025-40635 – Comerzzia Backoffice: Sales Orchestrator SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-40635 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]
CVE-2025-30193 – DNSdist TCP Stack Exhaustion Denial of Service Vulnerability
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy […]
CVE-2025-40634 – TP-Link Archer AX50 Router Stack-based Buffer Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-40634 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]
CVE-2025-40633 – Koibox Stored Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2025-40633 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]
CVE-2025-37892 – Linux Kernel MTD INFTL Buffer Overflow
The following table lists the changes that have been made to the CVE-2025-37892 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 May. 20, 2025 Action […]
CVE-2025-4951 – Rapid7 AppSpider Pro Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-4951 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 20, 2025 Action […]
CVE-2024-5878 – WordPress SimpleLightbox Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-5878 Published : May 20, 2025, 8:15 a.m. | 26 minutes ago Description : Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin’s bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for […]
CVE-2025-4322 – WordPress Motors Theme Privilege Escalation Vulnerability
CVE ID : CVE-2025-4322 Published : May 20, 2025, 6:15 a.m. | 25 minutes ago Description : The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user’s identity prior to updating their password. This […]
CVE-2025-2929 – “WordPress Order Delivery Date Reflected Cross-Site Scripting”
CVE ID : CVE-2025-2929 Published : May 20, 2025, 6:15 a.m. | 25 minutes ago Description : The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin […]