CVE-2025-40683 – Oracle Human Resource Management System Reflected XSS
The following table lists the changes that have been made to the CVE-2025-40683 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]
CVE-2025-40682 – Human Resource Management System SQL Injection
The following table lists the changes that have been made to the CVE-2025-40682 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jul. 29, 2025 Action […]
CVE-2025-5587 – WordPress Appzend Stored Cross-Site Scripting (XSS)
CVE ID : CVE-2025-5587 Published : July 29, 2025, 12:15 p.m. | 24 minutes ago Description : The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with […]
CISA Adds Cisco ISE and PaperCut Vulnerabilities to Known Exploited Vulnerabilities Catalog
CISA Adds Cisco ISE and PaperCut Vulnerabilities to Known Exploited Vulnerabilities Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert, adding three high-impact vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These inclu … Read more Published Date: Jul 29, 2025 (2 hours, 29 minutes ago) Vulnerabilities has been mentioned in this […]
Microsoft: macOS-kwetsbaarheid kan Apple Intelligence-informatie lekken
Microsoft: macOS-kwetsbaarheid kan Apple Intelligence-informatie lekken Onderzoekers van Microsoft hebben een kwetsbaarheid in macOS gevonden waardoor een applicatie onder andere gevoelige Apple Intelligence-informatie kan stelen. Apple kwam eind maart met een beveiliging … Read more Published Date: Jul 29, 2025 (1 hour, 2 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-31199
CVE-2025-8216 – Sky Addons for Elementor Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-8216 Published : July 29, 2025, 10:15 a.m. | 24 minutes ago Description : The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]
CVE-2025-7689 – Hydra Booking WordPress Privilege Escalation
CVE ID : CVE-2025-7689 Published : July 29, 2025, 10:15 a.m. | 24 minutes ago Description : The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to […]
CVE-2025-8196 – Elementor Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-8196 Published : July 29, 2025, 10:15 a.m. | 24 minutes ago Description : The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Custom Attributes in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. […]
CVE-2025-6730 – WooCommerce Free Gifts Lite – Unauthenticated Data Modification Vulnerability
CVE ID : CVE-2025-6730 Published : July 29, 2025, 10:15 a.m. | 24 minutes ago Description : The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the xlo_optin_call() function in all versions up to, and including, 1.0.0. This makes it possible […]
CVE-2025-6692 – YouTube Embed for WordPress Stored Cross-Site Scripting
CVE ID : CVE-2025-6692 Published : July 29, 2025, 10:15 a.m. | 24 minutes ago Description : The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all versions up to, and including, 10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, […]