Aggregator
CVE-2018-4435 | Apple tvOS up to 12.1 Kernel input validation (HT209342 / EDB-45960)
7 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Apple tvOS up to 12.1. This affects an unknown part of the component Kernel. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2018-4435. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24549 | Mahbubur Rahman Post Meta Plugin up to 1.0.9 on WordPress cross-site request forgery
7 months 3 weeks ago
A vulnerability was found in Mahbubur Rahman Post Meta Plugin up to 1.0.9 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-24549. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24560 | Awesome TOGI Awesome Event Booking Plugin up to 2.7.1 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in Awesome TOGI Awesome Event Booking Plugin up to 2.7.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24560. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24609 | PortOne 우커머스 결제 Plugin up to 3.2.4 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in PortOne 우커머스 결제 Plugin up to 3.2.4 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-24609. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24608 | Milan Petrovic GD Mail Queue Plugin up to 4.3 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in Milan Petrovic GD Mail Queue Plugin up to 4.3 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24608. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24535 | SKT Themes SKT Donation Plugin up to 1.9 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability has been found in SKT Themes SKT Donation Plugin up to 1.9 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-24535. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24534 | Emili Castells DPortfolio Plugin up to 2.0 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Emili Castells DPortfolio Plugin up to 2.0 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-24534. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24632 | AlgolPlus Advanced Dynamic Pricing for WooCommerce Plugin up to 4.9.0 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in AlgolPlus Advanced Dynamic Pricing for WooCommerce Plugin up to 4.9.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24632. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24551 | OneTeamSoftware Radio Buttons and Swatches for WooCommerce Plugin up to 1.1.20 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability classified as problematic was found in OneTeamSoftware Radio Buttons and Swatches for WooCommerce Plugin up to 1.1.20 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24551. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24597 | UkrSolution Barcode Generator for WooCommerce Plugin up to 2.0.2 on WordPress insertion of sensitive information into sent data
7 months 3 weeks ago
A vulnerability classified as problematic has been found in UkrSolution Barcode Generator for WooCommerce Plugin up to 2.0.2 on WordPress. Affected is an unknown function. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is traded as CVE-2025-24597. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24563 | ThemeGlow Cleanup Plugin up to 1.0.4 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in ThemeGlow Cleanup Plugin up to 1.0.4 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24563. The attack may be initiated remotely. There is no exploit available.
vuldb.com
新发现小行星有 1/83 的概率在 2032 年撞击地球
7 months 3 weeks ago
天文学家发现一颗新确定的小行星有 1/83 的概率在 2032 年 12 月 22 日撞击地球,但最可能情景是近距离飞过。这颗小行星编号为 2024 YR4,直径为 196 英尺,约为足球场长度的一半,目前距离地球 2700 万英里。NASA 的 Center of NEO Studies (CNEOS)估计,2024 YR4 将于 2032 年 12 月 22 日到达最近点,大约距离地球 106,200 公里。鉴于轨道的不确定性,它有可能会直接撞击地球。此类撞击可能会在大气层中制造“空爆”,或者在撞击地面时形成撞击坑。最可能的撞击地点从南美洲到大西洋到撒哈拉以南非洲。
Cisco’s Webex Chat Vulnerabilities Let Attackers Access Organizations Chat Histories
7 months 3 weeks ago
Cisco’s Webex Chat (formerly known as IMI Chat) was found to have a significant security flaw that exposed the sensitive chat histories of hundreds to thousands of organizations. The exploit allowed unauthorized attackers to access millions of live customer support messages, potentially compromising sensitive customer and organizational data. This flaw affected both internal help desk […]
The post Cisco’s Webex Chat Vulnerabilities Let Attackers Access Organizations Chat Histories appeared first on Cyber Security News.
Guru Baran
CVE-2025-24549 | Mahbubur Rahman Post Meta Plugin up to 1.0.9 on WordPress cross-site request forgery
7 months 3 weeks ago
A vulnerability was found in Mahbubur Rahman Post Meta Plugin up to 1.0.9 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-24549. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24560 | Awesome TOGI Awesome Event Booking Plugin up to 2.7.1 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in Awesome TOGI Awesome Event Booking Plugin up to 2.7.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24560. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24609 | PortOne 우커머스 결제 Plugin up to 3.2.4 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in PortOne 우커머스 결제 Plugin up to 3.2.4 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-24609. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24608 | Milan Petrovic GD Mail Queue Plugin up to 4.3 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability was found in Milan Petrovic GD Mail Queue Plugin up to 4.3 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24608. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24535 | SKT Themes SKT Donation Plugin up to 1.9 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability has been found in SKT Themes SKT Donation Plugin up to 1.9 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-24535. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24534 | Emili Castells DPortfolio Plugin up to 2.0 on WordPress cross site scripting
7 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Emili Castells DPortfolio Plugin up to 2.0 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-24534. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com