CVE-2025-8470 – SourceCodester Online Hotel Reservation System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-8470 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 02, 2025 Action […]

CVE-2025-8469 – SourceCodester Online Hotel Reservation System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-8469 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 02, 2025 Action […]

CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign

CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign Telecommunications organizations in Southeast Asia have been targeted by a state-sponsored threat actor known as CL-STA-0969 to facilitate remote control over compromised networks. Palo Alto Networks … Read more Published Date: Aug 02, 2025 (3 hours, 16 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-8468 – Code-projects Wazifa System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-8468 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 02, 2025 Action […]

CVE-2025-7710 – “Brave Conversion Engine WordPress Facebook Authentication Bypass”

CVE ID : CVE-2025-7710 Published : Aug. 2, 2025, 12:15 p.m. | 1 hour, 54 minutes ago Description : The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This […]

CVE-2025-8467 – Code-Projects Wazifa System SQL Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-8467 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 02, 2025 Action […]

CVE-2025-8488 – Elementor Header & Footer Builder Unauthorized Data Modification Vulnerability

CVE ID : CVE-2025-8488 Published : Aug. 2, 2025, 10:15 a.m. | 1 hour, 50 minutes ago Description : The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, […]

CVE-2025-6722 – BitFire Security – WordPress Firewall, WAF, Bot/Spam Blocker, Login Security Sensitive Information Exposure

CVE ID : CVE-2025-6722 Published : Aug. 2, 2025, 10:15 a.m. | 1 hour, 50 minutes ago Description : The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially […]

CVE-2025-8400 – WordPress Image Gallery Reflected Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-8400 Published : Aug. 2, 2025, 9:15 a.m. | 35 minutes ago Description : The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web […]