CVE-2025-4392 – WordPress Shared Files Frontend Stored Cross-Site Scripting
CVE ID : CVE-2025-4392 Published : June 3, 2025, 10:15 a.m. | 1 hour, 59 minutes ago Description : The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization […]
CVE-2025-31359 – Parallels Desktop Directory Traversal Vulnerability
The following table lists the changes that have been made to the CVE-2025-31359 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]
CVE-2024-52561 – Parallels Desktop for Mac Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2024-52561 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Jun. 03, 2025 Action Type […]
CVE-2024-36486 – Parallels Desktop for Mac Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2024-36486 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Jun. 03, 2025 Action Type […]
BitoPro Silent on $11.5M Hack: Investigator Uncovers Massive Crypto Theft
BitoPro Silent on $11.5M Hack: Investigator Uncovers Massive Crypto Theft Cryptocurrency investigator @zachxbt, while analyzing on-chain transactions, uncovered a suspicious movement of funds linked to the Taiwanese cryptocurrency exchange BitoPro. Approximately $11.5 milli … Read more Published Date: Jun 03, 2025 (2 hours, 17 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-4428 CVE-2025-4427 CVE-2024-21762 CVE-2022-47945
New ModSecurity WAF Vulnerability Let Attackers Crash the System
New ModSecurity WAF Vulnerability Let Attackers Crash the System A significant denial of service vulnerability has been discovered in ModSecurity, one of the most widely deployed open-source web application firewall (WAF) engines used to protect Apache, IIS, and Ng … Read more Published Date: Jun 03, 2025 (2 hours, 24 minutes ago) Vulnerabilities has been mentioned in […]
CVE-2025-5116 – WordPress WP Plugin Info Card Stored Cross-Site Scripting
CVE ID : CVE-2025-5116 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for […]
CVE-2025-5103 – WooCommerce Ultimate Gift Cards SQL Injection Vulnerability
CVE ID : CVE-2025-5103 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘default_price’ and ‘product_id’ parameters in all versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and […]
CVE-2025-4420 – Vayu Blocks Stored Cross-Site Scripting (XSS) in WordPress
CVE ID : CVE-2025-4420 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on the […]
CVE-2025-1725 – WordPress Bit File Manager Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1725 Published : June 3, 2025, 9:15 a.m. | 56 minutes ago Description : The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due […]