Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents
Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents A high-severity vulnerability was uncovered in Splunk Universal Forwarder for Windows that compromises directory access controls. The flaw, designated CVE-2025-20298 with a CVSSv3.1 score of 8.0, affe … Read more Published Date: Jun 03, 2025 (1 hour, 55 minutes ago) Vulnerabilities has been mentioned in this […]
CVE-2025-5340 – Elementor Music Player Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-5340 Published : June 3, 2025, 12:15 p.m. | 2 hours, 16 minutes ago Description : The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2025-4671 – WordPress Profile Builder Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-4671 Published : June 3, 2025, 12:15 p.m. | 2 hours, 16 minutes ago Description : The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied […]
CVE-2025-4205 – WordPress Popup Maker Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-4205 Published : June 3, 2025, 12:15 p.m. | 2 hours, 16 minutes ago Description : The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID’ parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]
CVE-2025-5493 – Baison Channel Middleware SQL Injection
The following table lists the changes that have been made to the CVE-2025-5493 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]
CVE-2025-5492 – D-Link DI-500WF-WT Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-5492 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]
New Linux Vulnerabilities
New Linux Vulnerabilities They’re interesting: Tracked as CVE-2025-5054 and CVE-2025-4598, both vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools … Read more Published Date: Jun 03, 2025 (3 hours, 8 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-5054 CVE-2025-4598
Google patches new Chrome zero-day bug exploited in attacks
Google patches new Chrome zero-day bug exploited in attacks Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year. “Google is aware that an exploit for CVE-2025-5419 exi … Read more Published Date: Jun 03, 2025 (1 hour, 50 minutes ago) Vulnerabilities has been mentioned […]
SolarWinds Dameware Remote Control Service Vulnerability Allows Privilege Escalation
SolarWinds Dameware Remote Control Service Vulnerability Allows Privilege Escalation A significant vulnerability, CVE-2025-26396, affects the SolarWinds Dameware Mini Remote Control Service could allow attackers to escalate privileges on affected systems. Security researcher Alexander … Read more Published Date: Jun 03, 2025 (1 hour, 55 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-26396
CVE-2024-54189 – Parallels Desktop for Mac Root Privilege Escalation
The following table lists the changes that have been made to the CVE-2024-54189 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Jun. 03, 2025 Action Type […]