CVE-2025-66314 – ZTE ElasticNet UME R32 ACL Privilege Escalation Vulnerability

The following table lists the changes that have been made to the CVE-2025-66314 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]

CVE-2025-13762 – Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305

The following table lists the changes that have been made to the CVE-2025-13762 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]

CVE-2025-34351 – Anyscale Ray v2.52.0 Token Authentication Disabled by Default Insecure Configuration

The following table lists the changes that have been made to the CVE-2025-34351 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]

CVE-2025-12578 – Reuters Direct <= 3.0.0 – Cross-Site Request Forgery to Settings Reset

CVE ID : CVE-2025-12578 Published : Nov. 27, 2025, 2:26 a.m. | 52 minutes ago Description : The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the the ‘class-reuters-direct-settings.php’ page. This makes it possible for […]