Currently trending CVE - hypeScore: 5 - A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitiv
Researchers spotted North Korea’s Kimsuky APT group launching spear-phishing attacks to deliver forceCopy info-stealer malware. Researchers from AhnLab Security Intelligence Center (ASEC) observed North Korea’s Kimsuky APT group conducting spear-phishing attacks to deliver forceCopy info-stealer malware. Kimsuky cyberespionage group (aka ARCHIPELAGO, Black Banshee, Thallium, Velvet Chollima, APT43) was first spotted by Kaspersky researchers in 2013. The group works under the control […]
A vulnerability was found in IBM Security Directory Integrator and Security Verify Directory Integrator 7.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to sensitive cookie without secure attribute.
The identification of this vulnerability is CVE-2024-28770. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in IBM Security Directory Integrator and Security Verify Directory Integrator 7.2.0 and classified as problematic. This issue affects some unknown processing. The manipulation leads to sensitive cookie without secure attribute.
The identification of this vulnerability is CVE-2024-28771. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in WP Triggers Lite Plugin up to 2.5.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-13095. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in IBM InfoSphere Master Data Management 11.6/12.0/14.0. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-46187. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to clickjacking.
The identification of this vulnerability is CVE-2025-0729. The attack may be initiated remotely. There is no exploit available.
The vendor was contacted early. They reacted very professional and provided a pre-fix version for their customers.
It is recommended to upgrade the affected component.
The vendor was contacted early. They reacted very professional and provided a pre-fix version for their customers.
A vulnerability has been found in MetaSlider Responsive Slider Plugin up to 3.92.0 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-24533. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in WP Busters Passwordless Plugin up to 1.1.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-23792. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Simple Locator Plugin up to 2.0.4 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-22513. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Clodeo Shipdeo Plugin up to 1.2.8 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23457. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in David F. Carr RSVPMaker Volunteer Roles Plugin up to 1.5.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-23531. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Jonathan Lau CubePM Plugin up to 1.0 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-23574. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic was found in CGD Arrange Terms Plugin up to 1.1.3 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-23752. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in Ulrich Sossou The Loops Plugin up to 1.0.2 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-23754. The attack may be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Ivan Chernyakov LawPress Plugin up to 1.4.5 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23756. It is possible to launch the attack remotely. There is no exploit available.