CVE-2025-7648 – Ruven Themes WordPress Stored Cross-Site Scripting
The following table lists the changes that have been made to the CVE-2025-7648 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]
CVE-2025-6813 – Apacheaapanel WordPress Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2025-6813 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]
CVE-2025-6781 – Copymatic – WordPress CSRF (Cross-Site Request Forgery)
The following table lists the changes that have been made to the CVE-2025-6781 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]
CVE-2025-6053 – Zuppler Online Ordering for WordPress CSRF
The following table lists the changes that have been made to the CVE-2025-6053 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]
CVE-2025-5816 – “WooCommerce Pengiriman Plugin Insecure Direct Object Reference”
The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the get_order_detail() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other […]
CVE-2025-3740 – “WordPress School Management System Local File Inclusion Vulnerability”
The School Management System for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the ‘page’ parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code […]
CVE-2025-20337: Cisco ISE Critical RCE Vulnerability
CVE-2025-20337: Cisco ISE Critical RCE Vulnerability Skip to content July 18, 2025SummaryCVE-2025-20337 is a critical remote code execution (RCE) vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE- … Read more Published Date: Jul 18, 2025 (2 hours, 31 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-20337 CVE-2025-6558 CVE-2025-20282 CVE-2025-20281 CVE-2025-32896 […]
CVE-2025-7431 – WordPress Knowledge Base Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-7431 Published : July 18, 2025, 2:15 a.m. | 59 minutes ago Description : The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated […]
CVE-2025-7767 – PHPGurukul Art Gallery Management System Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2025-7767 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 18, 2025 Action […]
GhostContainer: Kaspersky Uncovers Stealthy Backdoor Infiltrating Government & High-Tech Exchange Servers
GhostContainer: Kaspersky Uncovers Stealthy Backdoor Infiltrating Government & High-Tech Exchange Servers In a recent incident response operation, Kaspersky Labs uncovered a highly sophisticated backdoor named GhostContainer, designed to infiltrate Microsoft Exchange infrastructure within government and h … Read more Published Date: Jul 18, 2025 (10 hours, 56 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-34300 […]