MongoDB Server Pre-Authentication Vulnerability Let Attackers Trigger DoS Condition

A critical pre-authentication denial of service vulnerability was identified as CVE-2025-6709, affecting multiple versions of MongoDB Server across its 6.0, 7.0, and 8.0 release branches.
Summary1. Mo …
Read more

Published Date:
Jun 27, 2025 (4 hours, 36 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-6709

Read More

CVE ID : CVE-2025-49885

Published : June 27, 2025, 12:15 p.m. | 2 hours, 14 minutes ago

Description : Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) – WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Drag and Drop Multiple File Upload (Pro) – WooCommerce: from n/a through 5.0.6.

Severity: 10.0 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Read More

CVE ID : CVE-2025-49886

Published : June 27, 2025, 12:15 p.m. | 2 hours, 14 minutes ago

Description : Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) vulnerability in WebGeniusLab Zikzag Core allows PHP Local File Inclusion. This issue affects Zikzag Core: from n/a through 1.4.5.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Read More

CVE ID : CVE-2025-52709

Published : June 27, 2025, 12:15 p.m. | 2 hours, 14 minutes ago

Description : Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms allows Object Injection. This issue affects Everest Forms: from n/a through 3.2.2.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Read More