The China-sponsored state espionage group has exploited known, older bugs in Cisco gear for successful cyber intrusions on six continents in the past two months.
A vulnerability was found in Add Custom Content After Post Plugin up to 1.0 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23652. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in wjharil AdsMiddle Plugin up to 1.0 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-23648. The attack may be initiated remotely. There is no exploit available.
A vulnerability has been found in Ariagle WP-Clap Plugin up to 1.5 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-23647. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Scroll Top Plugin up to 1.3.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23651. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in Contact Form 7 Plugin up to 1.2.3 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-23655. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in WordPress-to-candidate for Salesforce CRM Plugin up to 1.0.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-23657. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Form To Online Booking Plugin up to 1.0 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23653. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in razvypp Tidy.ro Plugin up to 1.3 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-23650. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Apache EventMesh up to 1.10.x. It has been declared as critical. This vulnerability affects unknown code of the component eventmesh-meta-raft Plugin Module. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-56180. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Matt Brooks Library Instruction Recorder Plugin up to 1.1.4 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23646. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in WatchGuard Fireware OS up to 12.5.12+701324/12.11 and classified as problematic. Affected by this issue is some unknown functionality of the component SpamBlocker Module. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-1071. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in PTT HGS Mobile App up to 6.4.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposed dangerous routine.
This vulnerability is known as CVE-2024-12651. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in WatchGuard Fireware OS up to 12.5.12+701324/12.11. Affected is an unknown function of the component Blocked Sites List. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-1239. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in fredsted WP Login Attempt Log Plugin up to 1.3 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-23568. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Craig Edmunds Recip.ly Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23598. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Internal Links Generator Plugin up to 3.51 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-23571. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Mark Winiarski WPLingo Plugin up to 1.1.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-23534. The attack can be launched remotely. There is no exploit available.