Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents

Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents A high-severity vulnerability was uncovered in Splunk Universal Forwarder for Windows that compromises directory access controls. The flaw, designated CVE-2025-20298 with a CVSSv3.1 score of 8.0, affe … Read more Published Date: Jun 03, 2025 (1 hour, 55 minutes ago) Vulnerabilities has been mentioned in this […]

CVE-2025-5340 – Elementor Music Player Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-5340 Published : June 3, 2025, 12:15 p.m. | 2 hours, 16 minutes ago Description : The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible […]

CVE-2025-4671 – WordPress Profile Builder Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-4671 Published : June 3, 2025, 12:15 p.m. | 2 hours, 16 minutes ago Description : The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied […]

CVE-2025-4205 – WordPress Popup Maker Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-4205 Published : June 3, 2025, 12:15 p.m. | 2 hours, 16 minutes ago Description : The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID’ parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]

CVE-2025-5493 – Baison Channel Middleware SQL Injection

The following table lists the changes that have been made to the CVE-2025-5493 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]

CVE-2025-5492 – D-Link DI-500WF-WT Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-5492 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jun. 03, 2025 Action […]

New Linux Vulnerabilities

New Linux Vulnerabilities They’re interesting: Tracked as CVE-2025-5054 and CVE-2025-4598, both vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools … Read more Published Date: Jun 03, 2025 (3 hours, 8 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-5054 CVE-2025-4598

Google patches new Chrome zero-day bug exploited in attacks

Google patches new Chrome zero-day bug exploited in attacks Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year. “Google is aware that an exploit for CVE-2025-5419 exi … Read more Published Date: Jun 03, 2025 (1 hour, 50 minutes ago) Vulnerabilities has been mentioned […]

SolarWinds Dameware Remote Control Service Vulnerability Allows Privilege Escalation

SolarWinds Dameware Remote Control Service Vulnerability Allows Privilege Escalation A significant vulnerability, CVE-2025-26396, affects the SolarWinds Dameware Mini Remote Control Service could allow attackers to escalate privileges on affected systems. Security researcher Alexander … Read more Published Date: Jun 03, 2025 (1 hour, 55 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-26396

CVE-2024-54189 – Parallels Desktop for Mac Root Privilege Escalation

The following table lists the changes that have been made to the CVE-2024-54189 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by af854a3a-2127-422b-91ae-364da2661108 Jun. 03, 2025 Action Type […]