CVE-2025-4392 – WordPress Shared Files Frontend Stored Cross-Site Scripting

CVE ID : CVE-2025-4392 Published : June 3, 2025, 10:15 a.m. | 1 hour, 59 minutes ago Description : The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization […]

CVE-2025-31359 – Parallels Desktop Directory Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-31359 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]

CVE-2024-52561 – Parallels Desktop for Mac Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2024-52561 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Jun. 03, 2025 Action Type […]

CVE-2024-36486 – Parallels Desktop for Mac Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2024-36486 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Jun. 03, 2025 Action Type […]

BitoPro Silent on $11.5M Hack: Investigator Uncovers Massive Crypto Theft

BitoPro Silent on $11.5M Hack: Investigator Uncovers Massive Crypto Theft Cryptocurrency investigator @zachxbt, while analyzing on-chain transactions, uncovered a suspicious movement of funds linked to the Taiwanese cryptocurrency exchange BitoPro. Approximately $11.5 milli … Read more Published Date: Jun 03, 2025 (2 hours, 17 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-4428 CVE-2025-4427 CVE-2024-21762 CVE-2022-47945

New ModSecurity WAF Vulnerability Let Attackers Crash the System

New ModSecurity WAF Vulnerability Let Attackers Crash the System A significant denial of service vulnerability has been discovered in ModSecurity, one of the most widely deployed open-source web application firewall (WAF) engines used to protect Apache, IIS, and Ng … Read more Published Date: Jun 03, 2025 (2 hours, 24 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-5116 – WordPress WP Plugin Info Card Stored Cross-Site Scripting

CVE ID : CVE-2025-5116 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for […]

CVE-2025-5103 – WooCommerce Ultimate Gift Cards SQL Injection Vulnerability

CVE ID : CVE-2025-5103 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘default_price’ and ‘product_id’ parameters in all versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and […]

CVE-2025-4420 – Vayu Blocks Stored Cross-Site Scripting (XSS) in WordPress

CVE ID : CVE-2025-4420 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on the […]