CVE-2025-13090 – WP Directory Kit
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, […]
CVE-2025-41744 – Sprecher Automation: SPRECON-E series has static default key material for TLS connections
The following table lists the changes that have been made to the CVE-2025-41744 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 02, 2025 Action […]
CVE-2025-41743 – Sprecher Automation: SPRECON-E series prone to weak encryption of update files
The following table lists the changes that have been made to the CVE-2025-41743 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 02, 2025 Action […]
CVE-2025-41742 – Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system components
The following table lists the changes that have been made to the CVE-2025-41742 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 02, 2025 Action […]
CVE-2025-13353 – gokey allows secret recovery from a seed file without the master password
In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM authentication tag of the key seed. This issue has been fixed in gokey version 0.2.0. This is a breaking change. The fix has invalidated any passwords/secrets that were derived from […]
Google brengt updates uit voor twee actief aangevallen Android-lekken
Google brengt updates uit voor twee actief aangevallen Android-lekken Tijdens de laatste patchronde van dit jaar heeft Google beveiligingsupdates voor Android uitgebracht, die onder andere twee actief aangevallen kwetsbaarheden verhelpen. Daarnaast is er ook een kritiek … Read more Published Date: Dec 02, 2025 (49 minutes ago) Vulnerabilities has been mentioned in this article.
Vulnerability in OpenSolution QuickCMS software
Vulnerability in OpenSolution QuickCMS software Vulnerability in OpenSolution QuickCMS software CVE ID CVE-2025-12465 Publication date 02 December 2025 Vendor OpenSolution Product QuickCMS Vulnerable versions 6.8 Vulnerability type (CWE) Improper N … Read more Published Date: Dec 02, 2025 (3 hours, 5 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-12465
How a noisy ransomware intrusion exposed a long-term espionage foothold
How a noisy ransomware intrusion exposed a long-term espionage foothold Getting breached by two separate and likely unconnected cyber attack groups is a nightmare scenario for any organization, but can result in an unexpected silver lining: the noisier intrusion can draw … Read more Published Date: Dec 02, 2025 (3 hours, 8 minutes ago) Vulnerabilities has been […]
CVE-2025-13873 – The feature to import a survey is prone to stored Cross-Site Script attacks
The following table lists the changes that have been made to the CVE-2025-13873 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 64c5ae8f-7972-4697-86a0-7ada793ac795 Dec. 02, 2025 Action […]
CVE-2025-13872 – Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio
The following table lists the changes that have been made to the CVE-2025-13872 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 64c5ae8f-7972-4697-86a0-7ada793ac795 Dec. 02, 2025 Action […]