20-Year-Old Vulnerability Allows Hackers to Control Train Brakes

20-Year-Old Vulnerability Allows Hackers to Control Train Brakes CISA has issued a critical advisory warning about a severe vulnerability in railway communication systems that could allow attackers to control train brakes remotely. The vulnerability, assigned CVE-2 … Read more Published Date: Jul 15, 2025 (2 hours, 22 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-1727

CVE-2025-7367 – WordPress Strong Testimonials Stored Cross-Site Scripting

CVE ID : CVE-2025-7367 Published : July 15, 2025, 5:15 a.m. | 41 minutes ago Description : The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]

CVE-2025-7340 – “Elementor HT Contact Form Widget File Upload Vulnerability”

CVE ID : CVE-2025-7340 Published : July 15, 2025, 5:15 a.m. | 41 minutes ago Description : The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload function in all versions up to, […]

CVE-2025-5394 – Alone – Charity Multipurpose Non-profit WordPress Theme Unauthenticated Arbitrary File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2025-5394 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 15, 2025 Action […]

CVE-2025-5393 – WordPress Alone Charity Multipurpose Non-profit Theme Arbitrary File Deletion Vulnerability

The following table lists the changes that have been made to the CVE-2025-5393 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 15, 2025 Action […]

CVE-2025-6265 – Zyxel NWA50AX PRO Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-6265 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 15, 2025 Action […]

CVE-2025-53833 (CVSS 10): Critical SSTI Flaw in LaRecipe Threatens Millions of Laravel Apps

CVE-2025-53833 (CVSS 10): Critical SSTI Flaw in LaRecipe Threatens Millions of Laravel Apps A newly discovered Server-Side Template Injection (SSTI) vulnerability in the widely-used LaRecipe documentation tool has been assigned CVE-2025-53833 and scored a perfect 10.0 CVSS, indicating critic … Read more Published Date: Jul 15, 2025 (5 hours, 57 minutes ago) Vulnerabilities has been mentioned in […]

ImageMagick Flaw (CVE-2025-53101): Stack Buffer Overflow Allows Potential Remote Code Execution

ImageMagick Flaw (CVE-2025-53101): Stack Buffer Overflow Allows Potential Remote Code Execution A flaw has been discovered in ImageMagick, the widely used open-source image manipulation suite, that could lead to stack buffer overflows under specific conditions involving image filename templates. … Read more Published Date: Jul 15, 2025 (7 hours, 20 minutes ago) Vulnerabilities has been mentioned in […]