Aggregator
Cisco修复统一通信平台严重漏洞(CVE-2025-20309):默认Root账号可被远程接管
2 months 1 week ago
安全客
Google发布VeO 3视频生成模型:AI助力电影级画面创作正式开放使用
2 months 1 week ago
安全客
CVE-2025-49274 | Neom Blog Theme up to 0.0.9 on WordPress cross site scripting (EUVD-2025-19986)
2 months 1 week ago
A vulnerability classified as problematic has been found in Neom Blog Theme up to 0.0.9 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-49274. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-49247 | Team Showcase Plugin up to 25.05.12 on WordPress cross site scripting (EUVD-2025-19985)
2 months 1 week ago
A vulnerability was found in Team Showcase Plugin up to 25.05.12 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-49247. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50032 | Paytiko for WooCommerce Plugin up to 1.3.14 on WordPress authorization (EUVD-2025-19992)
2 months 1 week ago
A vulnerability was found in Paytiko for WooCommerce Plugin up to 1.3.14 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-50032. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-49866 | Nikel Beautiful Cookie Consent Banner Plugin up to 4.6.1 on WordPress cross site scripting (EUVD-2025-19989)
2 months 1 week ago
A vulnerability has been found in Nikel Beautiful Cookie Consent Banner Plugin up to 4.6.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-49866. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-47627 | LCweb PrivateContent Plugin up to 2.3.2 on WordPress filename control (EUVD-2025-19981)
2 months 1 week ago
A vulnerability has been found in LCweb PrivateContent Plugin up to 2.3.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is known as CVE-2025-47627. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-47634 | Keylor Mendoza WC Pickup Store Plugin up to 1.8.9 on WordPress authorization (EUVD-2025-19982)
2 months 1 week ago
A vulnerability classified as critical has been found in Keylor Mendoza WC Pickup Store Plugin up to 1.8.9 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-47634. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-47565 | ashanjay EventON Plugin up to 4.9.9 on WordPress authorization (EUVD-2025-19980)
2 months 1 week ago
A vulnerability was found in ashanjay EventON Plugin up to 4.9.9 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-47565. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-48231 | codepeople Booking Calendar Contact Form Plugin up to 1.2.58 on WordPress cross site scripting (EUVD-2025-19983)
2 months 1 week ago
A vulnerability was found in codepeople Booking Calendar Contact Form Plugin up to 1.2.58 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-48231. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-39487 | Rankie Plugin up to 1.8.2 on WordPress cross site scripting (EUVD-2025-19978)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Rankie Plugin up to 1.8.2 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-39487. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-28980 | machouinard Aviation Weather from NOAA Plugin up to 0.7.2 on WordPress path traversal (EUVD-2025-19972)
2 months 1 week ago
A vulnerability classified as critical was found in machouinard Aviation Weather from NOAA Plugin up to 0.7.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal.
This vulnerability is known as CVE-2025-28980. The attack can be launched remotely. There is no exploit available.
vuldb.com
闪耀国家级地标,360安全智能体定义安全未来
2 months 1 week ago
安全客
Weekly Threat Landscape Digest – Week 27
2 months 1 week ago
This week’s cyber threat landscape highlights a notable increase in zero-day exploit activity, sophisticated phishing campaigns, and the exploitation of […]
The post Weekly Threat Landscape Digest – Week 27 appeared first on HawkEye.
HawkEye
Полгода, 35 утечек, 39 миллионов записей: арифметика киберугроз в России
2 months 1 week ago
Роскомнадзор подвел итоги.
CVE-2025-32311 | Pressroom Theme up to 6.9 on WordPress cross site scripting (EUVD-2025-19977)
2 months 1 week ago
A vulnerability was found in Pressroom Theme up to 6.9 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-32311. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-28978 | SB Breadcrumbs Plugin up to 1.0 on WordPress cross site scripting (EUVD-2025-19971)
2 months 1 week ago
A vulnerability classified as problematic has been found in SB Breadcrumbs Plugin up to 1.0 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-28978. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-32297 | Simple Link Directory Plugin up to 14.7.3 on WordPress sql injection (EUVD-2025-19976)
2 months 1 week ago
A vulnerability, which was classified as critical, was found in Simple Link Directory Plugin up to 14.7.3 on WordPress. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-32297. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-28976 | dsrodzin Email Address Security by WebEmailProtector Plugin cross site scripting (EUVD-2025-19970)
2 months 1 week ago
A vulnerability has been found in dsrodzin Email Address Security by WebEmailProtector Plugin up to 3.3.6 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-28976. The attack can be initiated remotely. There is no exploit available.
vuldb.com