$540 Bounty: How a Misconfigured Warning Endpoint in Apache Airflow Exposed DAG Secrets
$540 Bounty: How a Misconfigured Warning Endpoint in Apache Airflow Exposed DAG Secrets CVE-2023–42780: An Improper Access Control Bug That Let Low-Privileged Users View DAG Import Errors and Stack TracesIntroWhen it comes to access control, “read-only” shouldn’t mean “see everything.” B … Read more Published Date: Jun 02, 2025 (4 hours, 3 minutes ago) Vulnerabilities has been […]
CVE-2025-5432 – AssamLook CMS SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5432 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 02, 2025 Action […]
CVE-2025-3951 – WordPress WP-Optimize SQL Injection Vulnerability
CVE ID : CVE-2025-3951 Published : June 2, 2025, 6:15 a.m. | 56 minutes ago Description : The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations. Severity: 0.0 […]
CVE-2025-5431 – AssamLook CMS SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5431 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 02, 2025 Action […]
CVE-2025-1485 – WordPress Real Cookie Banner Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1485 Published : June 2, 2025, 6:15 a.m. | 56 minutes ago Description : The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored […]
Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions
Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions Cybersecurity researchers have warned of a new spear-phishing campaign that uses a legitimate remote access tool called Netbird to target Chief Financial Officers (CFOs) and financial executives at ba … Read more Published Date: Jun 02, 2025 (2 hours, 37 minutes ago) Vulnerabilities has […]
CVE-2025-5430 – AssamLook CMS SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5430 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 02, 2025 Action […]
CVE-2025-5429 – Juzaweb CMS Remote Improper Access Control Vulnerability
The following table lists the changes that have been made to the CVE-2025-5429 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 02, 2025 Action […]
CVE-2025-49113 – Roundcube Webmail PHP Object Deserialization Vulnerability
The following table lists the changes that have been made to the CVE-2025-49113 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 02, 2025 Action […]
CVE-2025-49112 – Valkey TCP/IP Stack Integer Underflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-49112 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 02, 2025 Action […]