Chinese State Hackers Target Global Critical Infrastructure, NSA Warns

Chinese State Hackers Target Global Critical Infrastructure, NSA Warns A coalition of cybersecurity and intelligence agencies from across the globe, including the United States National Security Agency (NSA), has issued a joint advisory revealing ongoing cyber intrusions … Read more Published Date: Aug 28, 2025 (3 hours, 32 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-58322 – NAVER MYBOX Explorer Local Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-58322 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]

Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet

Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide. The flaw, designated CVE-2025-40779, allows remote attacke … Read more Published Date: Aug 28, 2025 (2 hours, 36 minutes ago) Vulnerabilities has been […]

CVE-2025-8073 – WooCommerce Dynamic AJAX Product Filters Stored Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-8073 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]

CVE-2025-6255 – WooCommerce Dynamic AJAX Product Filters Stored Cross-Site Scripting

The following table lists the changes that have been made to the CVE-2025-6255 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 28, 2025 Action […]

CVE-2025-7955 – RingCentral Communications WordPress Authentication Bypass

CVE ID : CVE-2025-7955 Published : Aug. 28, 2025, 6:15 a.m. | 1 hour, 3 minutes ago Description : The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply […]

CVE-2025-7956 – Apache Ajax Search Lite Information Exposure Vulnerability

CVE ID : CVE-2025-7956 Published : Aug. 28, 2025, 6:15 a.m. | 1 hour, 3 minutes ago Description : The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to […]

CVE-2024-13807 – Xagio SEO Plugin for WordPress Sensitive Information Exposure

CVE ID : CVE-2024-13807 Published : Aug. 28, 2025, 6:15 a.m. | 1 hour, 3 minutes ago Description : The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup functionality due to weak filename structure and lack of protection in the directory. This makes […]

CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks

CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Citrix NetScaler systems, designated as CVE-2025-7775. This memory overflow vulnerability enables remote code ex … Read more Published Date: Aug 28, 2025 (2 hours, 7 minutes ago) Vulnerabilities has been mentioned in this article. […]

CVE-2025-8977 – “WordPress Simple Download Monitor SQL Injection”

CVE ID : CVE-2025-8977 Published : Aug. 28, 2025, 5:15 a.m. | 2 hours, 3 minutes ago Description : The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient […]