Aggregator
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root
8 months 3 weeks ago
VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Disclosed on 29 September 2025, the advisory covers CVE-2025-41244, CVE-2025-41245, and CVE-2025-41246 with CVSSv3 base scores ranging from 4.9 to 7.8. Administrators must apply the patched versions […]
The post VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root appeared first on Cyber Security News.
Florence Nightingale
Что делать, если вы потеряли телефон Android? Самая полная инструкция на 2025 год
8 months 3 weeks ago
Как скрытые функции поиска дают шанс даже в безнадёжных ситуациях.
CVE-2025-60176 | WP Tesseract Plugin up to 1.0.2 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability was found in WP Tesseract Plugin up to 1.0.2 on WordPress. It has been declared as problematic. This issue affects some unknown processing. Executing manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-60176. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-60131 | Werk aan de Muur Plugin up to 1.5 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability was found in Werk aan de Muur Plugin up to 1.5 on WordPress. It has been classified as problematic. This vulnerability affects unknown code. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-60131. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-60132 | Video Blogster Lite Plugin up to 1.2 on WordPress cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in Video Blogster Lite Plugin up to 1.2 on WordPress and classified as problematic. This affects an unknown part. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-60132. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-60134 | WP Media Categories Plugin up to 2.1.0 on WordPress cross-site request forgery
8 months 3 weeks ago
A vulnerability has been found in WP Media Categories Plugin up to 2.1.0 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes cross-site request forgery.
This vulnerability is handled as CVE-2025-60134. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-60168 | HotelRunner Booking Widget Plugin up to 1.6 on WordPress cross-site request forgery
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in HotelRunner Booking Widget Plugin up to 1.6 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2025-60168. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-60183 | Silencesoft RSS Reader Plugin up to 0.6 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Silencesoft RSS Reader Plugin up to 0.6 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-60183. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-53324 | Gutenify Plugin up to 1.5.7 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability classified as problematic was found in Gutenify Plugin up to 1.5.7 on WordPress. This impacts an unknown function. Executing manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-53324. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-60135 | WeShare Buttons Plugin up to 13.0.0 on WordPress cross site scripting
8 months 3 weeks ago
A vulnerability classified as problematic has been found in WeShare Buttons Plugin up to 13.0.0 on WordPress. This affects an unknown function. Performing manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-60135. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-52773 | HieCOR Payment Gateway Plugin up to 1.5.11 on WordPress sql injection
8 months 3 weeks ago
A vulnerability described as critical has been identified in HieCOR Payment Gateway Plugin up to 1.5.11 on WordPress. The impacted element is an unknown function. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2025-52773. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2024-58040 | QWER Crypt::RandomEncryption up to 0.01 on Perl rand weak prng (EUVD-2024-55029)
8 months 3 weeks ago
A vulnerability marked as problematic has been reported in QWER Crypt::RandomEncryption up to 0.01 on Perl. The affected element is the function rand. This manipulation causes cryptographically weak prng.
This vulnerability is registered as CVE-2024-58040. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-59956 | coder agentapi up to 0.3.x Agent API /messages dns rebinding
8 months 3 weeks ago
A vulnerability labeled as problematic has been found in coder agentapi up to 0.3.x. Impacted is an unknown function of the file /messages of the component Agent API. The manipulation results in reliance on reverse dns resolution.
This vulnerability is cataloged as CVE-2025-59956. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-43815 | Liferay Portal/DXP cross site scripting (WID-SEC-2025-2151)
8 months 3 weeks ago
A vulnerability identified as problematic has been detected in Liferay Portal and DXP. This issue affects some unknown processing. The manipulation of the argument com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURLTitle leads to cross site scripting.
This vulnerability is listed as CVE-2025-43815. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-43818 | Liferay Portal/DXP Calendar Widget Name cross site scripting (WID-SEC-2025-2151)
8 months 3 weeks ago
A vulnerability categorized as problematic has been discovered in Liferay Portal and DXP. This vulnerability affects unknown code of the component Calendar Widget. Executing manipulation of the argument Name can lead to cross site scripting.
This vulnerability is tracked as CVE-2025-43818. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-43820 | Liferay Portal/DXP Calendar Widget First Name/Middle Name/Last Name cross site scripting (WID-SEC-2025-2151)
8 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been rated as problematic. This affects an unknown part of the component Calendar Widget. Performing manipulation of the argument First Name/Middle Name/Last Name results in cross site scripting.
This vulnerability is identified as CVE-2025-43820. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-43811 | Liferay Portal/DXP Asset Author First Name/Middle Name/Last Name cross site scripting (WID-SEC-2025-2151)
8 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Asset Author Handler. Such manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting.
This vulnerability is referenced as CVE-2025-43811. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-43812 | Liferay Portal/DXP Web Content Template cross site scripting (WID-SEC-2025-2151)
8 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Content Template. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-43812. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-43817 | Liferay Portal/DXP Announcement Handler/Alert redirect cross site scripting (WID-SEC-2025-2151)
8 months 3 weeks ago
A vulnerability was found in Liferay Portal and DXP and classified as problematic. Affected is an unknown function of the component Announcement Handler/Alert Handler. The manipulation of the argument redirect results in cross site scripting.
This vulnerability was named CVE-2025-43817. The attack may be performed from remote. There is no available exploit.
vuldb.com