Development

CVE ID : CVE-2025-3435

Published : April 24, 2025, 4:15 a.m. | 3 hours, 25 minutes ago

Description : The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Severity: 4.4 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-1453

Published : April 24, 2025, 6:15 a.m. | 1 hour, 25 minutes ago

Description : The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-2558

Published : April 24, 2025, 6:15 a.m. | 1 hour, 25 minutes ago

Description : The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32730

Published : April 24, 2025, 7:15 a.m. | 25 minutes ago

Description : Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.

Severity: 5.5 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-3761

Published : April 24, 2025, 7:15 a.m. | 25 minutes ago

Description : The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to that of an administrator.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

FormBook Malware Spreads via Sophisticated Phishing Attack

Workflow diagram of this FormBook campaign | Image: FortiGuard Labs
A new phishing campaign distributing the FormBook infostealer malware has been uncovered by Fortinet’s FortiGuard Labs, targeting Wi …
Read more

Published Date:
Apr 24, 2025 (3 hours, 32 minutes ago)

Vulnerabilities has been mentioned in this article.

Grafana Patches CVE-2025-3260 and More in Critical Security Update

Grafana Labs has issued security updates for multiple product versions, addressing one high and two medium-severity vulnerabilities affecting Grafana OSS and Enterprise editions. The most serious—CVE- …
Read more

Published Date:
Apr 24, 2025 (3 hours, 29 minutes ago)

Vulnerabilities has been mentioned in this article.

NVIDIA NeMo Framework: High-Risk Vulnerabilities Allow Remote Code Execution

NVIDIA has issued a security bulletin disclosing three high-severity vulnerabilities in its NeMo Framework, a scalable, cloud-native generative AI platform designed for developers working with Large L …
Read more

Published Date:
Apr 24, 2025 (3 hours, 16 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-23251

CVE-2025-23250

CVE-2025-23249

CVE-2024-6235: NetScaler Console Flaw Enables Admin Access, PoC Publishes

A critical vulnerability—CVE-2024-6235—in Citrix NetScaler Console has been dissected by security researcher chutton-r7, revealing a severe unauthenticated session hijack that enables attackers to cre …
Read more

Published Date:
Apr 24, 2025 (3 hours, 7 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2024-12284

CVE-2024-6236

CVE-2024-6235

CVE-2025-34028: Critical RCE Flaw in Commvault Command Center Scores CVSS 10

Commvault has disclosed a critical vulnerability affecting its Command Center, identified as CVE-2025-34028, with the maximum CVSS score of 10.0. The flaw allows unauthenticated remote attackers to ex …
Read more

Published Date:
Apr 24, 2025 (2 hours, 57 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32965

CVE-2025-34028

CVE-2025-32965: Backdoor in xrpl.js SDK Puts Crypto Wallets at Risk

Aikido Intel has issued an urgent alert after detecting a backdoor in multiple versions of xrpl.js, the official SDK for the XRP Ledger, marking one of the most severe supply chain attacks to hit the …
Read more

Published Date:
Apr 24, 2025 (2 hours, 44 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32965

CVE-2025-34028

High-Severity SonicWall SSLVPN Vulnerability Allows Firewall Crashing

SonicWall has disclosed a vulnerability affecting its SonicOS SSLVPN Virtual Office interface, which, if exploited, could allow remote attackers to crash firewall appliances. Tracked as CVE-2025-32818 …
Read more

Published Date:
Apr 24, 2025 (2 hours, 3 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32818

CVE-2025-32965

CVE-2024-53704

CVE-2024-40766

CVE-2023-0656

GitLab Releases Security Update to Patch XSS and Account Takeover Flaws

GitLab has issued a security advisory urging users to upgrade their self-managed GitLab installations immediately. The advisory highlights the release of versions 17.11.1, 17.10.5, and 17.9.7 for both …
Read more

Published Date:
Apr 24, 2025 (1 hour, 52 minutes ago)

Vulnerabilities has been mentioned in this article.

Redis Vulnerability Exposes Servers to Denial-of-Service Attacks

A high-severity vulnerability has been discovered in Redis, the popular open-source in-memory data structure store, which could allow unauthenticated users to exhaust server memory and cause a Denial- …
Read more

Published Date:
Apr 24, 2025 (1 hour, 39 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-21605

CVE-2024-31449

CVE-2023-41056

CVE-2022-35951

CVE ID : CVE-2024-22351

Published : April 23, 2025, 11:15 p.m. | 3 hours, 44 minutes ago

Description : IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Severity: 6.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-25045

Published : April 23, 2025, 11:15 p.m. | 3 hours, 44 minutes ago

Description : IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.

Severity: 4.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-25046

Published : April 23, 2025, 11:15 p.m. | 3 hours, 44 minutes ago

Description : IBM InfoSphere Information Server 11.7 DataStage Flow Designer 

transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.

Severity: 3.7 | LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more…