CVE-2025-40704 – OpenAtlas XSS: Unvalidated User Input in “/insert/edition” “/name” Parameter
The following table lists the changes that have been made to the CVE-2025-40704 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 29, 2025 Action […]
CVE-2025-40703 – OpenAtlas Cross-Site Scripting (XSS) Vulnerability
The following table lists the changes that have been made to the CVE-2025-40703 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 29, 2025 Action […]
CVE-2025-40702 – OpenAtlas ACDH-CH Cross-Site Scripting (XSS) Vulnerability
The following table lists the changes that have been made to the CVE-2025-40702 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 29, 2025 Action […]
Multiple Hikvision Vulnerabilities Let Attackers Inject Executable Commands
Multiple Hikvision Vulnerabilities Let Attackers Inject Executable Commands Hikvision has disclosed three significant security vulnerabilities affecting multiple versions of its HikCentral product suite that could enable attackers to execute malicious commands and gain unauth … Read more Published Date: Aug 29, 2025 (1 hour, 48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-39247 CVE-2025-39246 CVE-2025-39245
CVE-2025-9217 – Slider Revolution WordPress Path Traversal Vulnerability
CVE ID : CVE-2025-9217 Published : Aug. 29, 2025, 11:15 a.m. | 1 hour, 53 minutes ago Description : The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the ‘used_svg’ and ‘used_images’ parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to […]
CVE-2024-13342 – “Booster for WooCommerce Remote File Upload Vulnerability”
CVE ID : CVE-2024-13342 Published : Aug. 29, 2025, 11:15 a.m. | 1 hour, 53 minutes ago Description : The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ‘add_files_to_order’ function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers […]
Vulnerabilities in Payload CMS software
Vulnerabilities in Payload CMS software Vulnerabilities in Payload CMS software CVE ID CVE-2025-4643 Publication date 29 August 2025 Vendor Payload CMS Product Payload Vulnerable versions All before 3.44.0 Vulnerability type (CWE) Insuffici … Read more Published Date: Aug 29, 2025 (30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-4644 CVE-2025-4643
CVE-2025-9071 – Oberon PSA Crypto RSA Padding Vulnerability
The following table lists the changes that have been made to the CVE-2025-9071 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 29, 2025 Action […]
CVE-2025-7071 – Oberon Microsystems AG Ocrypto AES-CBC Padding Oracle Attack
The following table lists the changes that have been made to the CVE-2025-7071 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 29, 2025 Action […]
CVE-2025-4644 – Payload SQLite Adapter Session Fixation
A Session Fixation vulnerability existed in Payload’s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing […]