CVE-2025-6495 – Bricks WordPress Blind SQL Injection

CVE ID : CVE-2025-6495 Published : July 29, 2025, 5:15 a.m. | 1 hour, 17 minutes ago Description : The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on […]

CVE-2025-53649 – “SwitchBot Sensitive Information Exposure”

The following table lists the changes that have been made to the CVE-2025-53649 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]

CVE-2025-53080 – Samsung DMS Data Management Server Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-53080 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]

CVE-2025-53078 – Samsung DMS Deserialization Code Execution Vulnerability

The following table lists the changes that have been made to the CVE-2025-53078 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]

CVE-2025-53079 – Samsung DMS Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2025-53079 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]

CVE-2025-53077 – Samsung DMS Execution After Redirect Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-53077 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]

CVE-2025-4566 – Elementor Website Builder Stored Cross-Site Scripting

CVE ID : CVE-2025-4566 Published : July 29, 2025, 5:15 a.m. | 1 hour, 17 minutes ago Description : The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 […]

CVE-2025-4370 – Brizy – Page Builder Unauthenticated File Upload Vulnerability

CVE ID : CVE-2025-4370 Published : July 29, 2025, 5:15 a.m. | 1 hour, 17 minutes ago Description : The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing path validation in store_file function in all versions up to, and including, 2.6.20. […]

CVE-2025-3075 – Elementor Website Builder Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-3075 Published : July 29, 2025, 5:15 a.m. | 1 hour, 17 minutes ago Description : The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘elementor-element’ shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization […]

CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation

CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation Jul 29, 2025Ravie LakshmananVulnerability / Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperC … Read more Published Date: Jul 29, 2025 (2 hours, 20 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2023-2533