Crypto Crisis: UPBIT Hacked for $369 Million in Solana-Based Tokens
Crypto Crisis: UPBIT Hacked for $369 Million in Solana-Based Tokens South Korea’s largest cryptocurrency exchange, UPBIT, has suffered a major cyberattack. According to an official announcement from the exchange, digital assets worth 54 billion KRW (approximately USD … Read more Published Date: Nov 27, 2025 (1 hour, 58 minutes ago) Vulnerabilities has been mentioned in this article. […]
Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain
Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain A critical security vulnerability has been discovered in the Angular framework that could allow attackers to steal sensitive user security tokens. The vulnerability, tracked as CVE-2025-66035, affects … Read more Published Date: Nov 27, 2025 (2 hours, 2 minutes ago) Vulnerabilities has been mentioned in this article. […]
CVE-2025-59890 – Eaton Galileo Local File Inclusion Vulnerability
The following table lists the changes that have been made to the CVE-2025-59890 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-13742 – Limited HTML injection in emails
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer’s name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting […]
CVE-2025-10476 – WP Fastest Cache <= 1.4.0 – Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions
CVE ID : CVE-2025-10476 Published : Nov. 27, 2025, 11:15 a.m. | 22 minutes ago Description : The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, […]
CVE-2025-59026 – Apache File Upload Cross-Site Scripting
The following table lists the changes that have been made to the CVE-2025-59026 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-59025 – Apache Email Script Execution Vulnerability
The following table lists the changes that have been made to the CVE-2025-59025 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-30190 – Microsoft Office Document Code Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-30190 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-30186 – Apache File Upload Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2025-30186 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-13381 – AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 – Missing Authorization to Unauthenticated Media File Uploads
CVE ID : CVE-2025-13381 Published : Nov. 27, 2025, 10:15 a.m. | 1 hour, 22 minutes ago Description : The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ‘ays_chatgpt_save_wp_media’ function in all versions up to, and including, 2.7.0. This makes […]