CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks

CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitati … Read more Published Date: Jul 19, 2025 (1 hour, 51 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-25257

CVE-2025-7669 – Avishi WP PayPal Payment Button CSRF Vulnerability

The following table lists the changes that have been made to the CVE-2025-7669 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]

CVE-2025-7658 – WordPress Temporarily Hidden Content Stored Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-7658 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]

CVE-2025-7655 – WordPress Live Stream Badger Stored Cross-Site Scripting

The following table lists the changes that have been made to the CVE-2025-7655 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]

CVE-2025-7661 – Martinus Stored Cross-Site Scripting (XSS) in WordPress Partnerský systém

The following table lists the changes that have been made to the CVE-2025-7661 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]

CVE-2025-7653 – EPay.bg Payments Plugin for WordPress Stored Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-7653 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]

CVE-2025-52924 – One Identity OneLogin SQL Injection

The following table lists the changes that have been made to the CVE-2025-52924 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 19, 2025 Action […]

Major npm Supply Chain Attack: Phishing Campaign Steals Maintainer Credentials, Injects Malware into Popular Packages

Major npm Supply Chain Attack: Phishing Campaign Steals Maintainer Credentials, Injects Malware into Popular Packages Image: Socket A deceptive and highly targeted phishing campaign has successfully compromised several popular npm packages, including eslint-config-prettier, eslint-plugin-prettier, and synckit, after … Read more Published Date: Jul 19, 2025 (9 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. […]

FortiWeb SQL Injection (CVE-2025-25257) Added to CISA KEV After Active Exploitation, PoC Available!

FortiWeb SQL Injection (CVE-2025-25257) Added to CISA KEV After Active Exploitation, PoC Available! A critical SQL injection vulnerability in Fortinet FortiWeb, tracked as CVE-2025-25257, has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog following confirmation of active exploi … Read more Published Date: Jul 19, 2025 (9 hours, 32 minutes ago) Vulnerabilities has been mentioned […]

CVE-2025-54309: CrushFTP Targeted in Active Exploits Due to Unpatched Zero-Day Vulnerability

CVE-2025-54309: CrushFTP Targeted in Active Exploits Due to Unpatched Zero-Day Vulnerability CrushFTP, a widely used secure file transfer server, has issued an urgent advisory regarding a critical zero-day vulnerability, tracked as CVE-2025-54309 (CVSS 9.0), that has been actively exploited i … Read more Published Date: Jul 19, 2025 (9 hours, 48 minutes ago) Vulnerabilities has been mentioned […]