New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora
New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora Two information disclosure flaws have been identified in apport and systemd-coredump, the core dump handlers in Ubuntu, Red Hat Enterprise Linux, and Fedora, according to the Qualys Threat Research Un … Read more Published Date: May 31, 2025 (2 hours, 22 minutes ago) […]
CVE-2025-5374 – PHPGurukul Online Birth Certificate System SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5374 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 31, 2025 Action […]
CVE-2025-5373 – PHPGurukul Online Birth Certificate System SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5373 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 31, 2025 Action […]
CVE-2025-5371 – SourceCodester Health Center Patient Record Management System SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5371 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 31, 2025 Action […]
CVE-2025-5290 – Elementor Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-5290 Published : May 31, 2025, 8:15 a.m. | 27 minutes ago Description : The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it […]
CVE-2025-3813 – WordPress Royal Elementor Stored Cross-Site Scripting (XSS)
CVE ID : CVE-2025-3813 Published : May 31, 2025, 8:15 a.m. | 27 minutes ago Description : The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2025-5292 – Elementor Element Pack Addons Stored Cross-Site Scripting Vulnerability
The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_content’ parameter in all versions up to, and including, 5.11.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with […]
CVE-2025-5285 – WooCommerce Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-5285 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 31, 2025 Action […]
CVE-2025-4672 – Offsprout Page Builder WordPress Privilege Escalation Vulnerability
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() function in versions 2.2.1 to 2.15.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to read, create, update or delete any user meta, including flipping their own wp_capabilities to administrator and […]
CVE-2025-4631 – WordPress Profitori Plugin Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-4631 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 31, 2025 Action […]