Aggregator
Hidden Backdoors in npm Packages Let Attackers Wipe Entire Systems
Device ID: Your Secret Weapon Against Unauthorized Account Sharing
Unauthorized account sharing is a pervasive threat to digital platforms. This widespread issue—often perceived as harmless by consumers—is eating into your revenue, skewing your user metrics, and diminishing the experience for your legitimate customers. The cost is staggering, especially in the streaming industry. The habit of sharing online passwords to streaming and other subscription video-on-demand […]
The post Device ID: Your Secret Weapon Against Unauthorized Account Sharing appeared first on Security Boulevard.
CVE-2025-5952 | Zend.To up to 6.10-6 Beta NSSDropoff.php exec file_1 os command injection (EUVD-2025-17626)
CVE-2025-4387 | Abandoned Cart Pro for WooCommerce Plugin up to 9.16.0 on WordPress wcap_add_to_cart_popup_upload_files unrestricted upload (EUVD-2025-17622)
CVE-2025-3076 | Elementor Website Builder Pro Plugin up to 3.29.0 on WordPress button_text cross site scripting (EUVD-2025-17620)
CVE-2025-47561 | RomanCode MapSVG Plugin up to 8.5.34 on WordPress privileges assignment (EUVD-2025-17520)
CVE-2025-48279 | Richard Perdaan WC MyParcel Belgium Plugin up to beta on WordPress cross site scripting
Submit #589178: Zend.To Zend.to Before6.10-7 Beta Code Injection [Accepted]
CVE-2025-47527 | Icegram Collect Plugin up to 1.3.18 on WordPress authorization (EUVD-2025-17519)
CVE-2025-49297 | Mikado-Themes Grill and Chow Plugin up to 1.6 on WordPress path traversal (EUVD-2025-17551)
CVE-2025-49296 | Mikado-Themes GrandPrix Plugin up to 1.6 on WordPress path traversal
CVE-2025-49295 | Mikado-Themes MediClinic Plugin up to 2.1 on WordPress path traversal
CVE-2025-48281 | mystyleplatform MyStyle Custom Product Designer Plugin up to 3.21.1 on WordPress sql injection (EUVD-2025-17539)
CVE-2025-48261 | MultiVendorX Plugin up to 4.2.22 on WordPress insertion of sensitive information into sent data
CVE-2025-48141 | Alex Zaytseff Multi CryptoCurrency Payments Plugin up to 2.0.3 on WordPress sql injection
CVE-2025-48130 | spicethemes Spice Blocks Plugin up to 2.0.7.2 on WordPress path traversal
CVE-2025-49265 | WP Swings Membership for WooCommerce Plugin up to 2.8.1 on WordPress authorization
What is AI Red Teaming?
Stay updated on the latest in application security with the OWASP Top 10 vulnerabilities.
The post What is AI Red Teaming? appeared first on Security Boulevard.
OffensiveCon25 – Parser Differentials: When Interpretation Becomes a Vulnerability
Author/Presenter: Joernchen
Our sincere appreciation to OffensiveCon by Binary Gecko, and the Presenters/Authors for publishing their outstanding OffensiveCon 2025 video content. Originating from the conference’s events located at the Hilton Berlin; and via the organizations YouTube channel.
Thanks and a Tip O' The Hat to Verification Labs :: Penetration Testing Specialists :: Trey Blalock GCTI, GWAPT, GCFA, GPEN, GPCS, GCPN, CRISC, CISA, CISM, CISSP, SSCP, CDPSE for recommending the OffensiveCon 25 conference.
The post OffensiveCon25 – Parser Differentials: When Interpretation Becomes a Vulnerability appeared first on Security Boulevard.