Aggregator
Apache Tomcat and Camel Vulnerabilities Actively Targeted in Cyberattacks
2 months 2 weeks ago
The Apache Foundation disclosed several critical vulnerabilities affecting two of its widely used software platforms, Apache Tomcat and Apache Camel, sparking immediate concern among cybersecurity experts and organizations worldwide. Apache Tomcat, a popular platform for running Java-based web applications, was found to have a severe flaw identified as CVE-2025-24813. This vulnerability, impacting versions 9.0.0.M1 to […]
The post Apache Tomcat and Camel Vulnerabilities Actively Targeted in Cyberattacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-6041 | yContributors Plugin up to 0.5 on WordPress Setting cross-site request forgery (EUVD-2025-19925)
2 months 2 weeks ago
A vulnerability was found in yContributors Plugin up to 0.5 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-6041. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5933 | RD Contacto Plugin up to 1.4 on WordPress Setting rdWappUpdateData cross-site request forgery (EUVD-2025-19928)
2 months 2 weeks ago
A vulnerability has been found in RD Contacto Plugin up to 1.4 on WordPress and classified as problematic. Affected by this vulnerability is the function rdWappUpdateData of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-5933. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6039 | ProcessingJS Plugin up to 1.2.2 on WordPress pjs4wp cross site scripting (EUVD-2025-19914)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in ProcessingJS Plugin up to 1.2.2 on WordPress. Affected is the function pjs4wp. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-6039. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5924 | WP Firebase Push Notification Plugin up to 1.2.0 on WordPress wfpn_brodcast_notification_message cross-site request forgery (EUVD-2025-19916)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in WP Firebase Push Notification Plugin up to 1.2.0 on WordPress. This issue affects the function wfpn_brodcast_notification_message. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-5924. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-7046 | Portfolio for Elementor & Image Gallery Plugin up to 3.2.0/3.2.1 on WordPress cross site scripting (EUVD-2025-19927)
2 months 2 weeks ago
A vulnerability classified as problematic was found in Portfolio for Elementor & Image Gallery Plugin up to 3.2.0/3.2.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-7046. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6787 | Smart Docs Plugin up to 1.1.0 on WordPress Shortcode smartdocs_search cross site scripting (EUVD-2025-19918)
2 months 2 weeks ago
A vulnerability classified as problematic has been found in Smart Docs Plugin up to 1.1.0 on WordPress. This affects the function smartdocs_search of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-6787. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6238 | AI Engine Plugin 2.8.4/2.8.5 on WordPress Meow_MWAI_Labs_OAuth redirect_uri (EUVD-2025-19924)
2 months 2 weeks ago
A vulnerability was found in AI Engine Plugin 2.8.4/2.8.5 on WordPress. It has been rated as problematic. Affected by this issue is the function Meow_MWAI_Labs_OAuth. The manipulation of the argument redirect_uri leads to open redirect.
This vulnerability is handled as CVE-2025-6238. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-6729 | PayMaster for WooCommerce Plugin up to 0.4.31 on WordPress wp_ajax_paym_status server-side request forgery (EUVD-2025-19922)
2 months 2 weeks ago
A vulnerability was found in PayMaster for WooCommerce Plugin up to 0.4.31 on WordPress. It has been declared as critical. Affected by this vulnerability is the function wp_ajax_paym_status. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-6729. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6786 | DocCheck Login Plugin up to 1.1.5 on WordPress improper authentication (EUVD-2025-19929)
2 months 2 weeks ago
A vulnerability was found in DocCheck Login Plugin up to 1.1.5 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6786. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6782 | GoZen Forms Plugin up to 1.1.5 on WordPress dirGZActiveForm forms-id sql injection (EUVD-2025-19915)
2 months 2 weeks ago
A vulnerability was found in GoZen Forms Plugin up to 1.1.5 on WordPress and classified as critical. This issue affects the function dirGZActiveForm. The manipulation of the argument forms-id leads to sql injection.
The identification of this vulnerability is CVE-2025-6782. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6783 | GoZen Forms Plugin up to 1.1.5 on WordPress emdedSc ID sql injection (EUVD-2025-19917)
2 months 2 weeks ago
A vulnerability has been found in GoZen Forms Plugin up to 1.1.5 on WordPress and classified as critical. This vulnerability affects the function emdedSc. The manipulation of the argument ID leads to sql injection.
This vulnerability was named CVE-2025-6783. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6739 | WPQuiz Plugin up to 0.4.2 on WordPress Shortcode wpquiz sql injection (EUVD-2025-19926)
2 months 2 weeks ago
A vulnerability, which was classified as critical, was found in WPQuiz Plugin up to 0.4.2 on WordPress. This affects the function wpquiz of the component Shortcode Handler. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-6739. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6814 | Booking X Plugin up to 1.1.2 on WordPress HTTP POST Request export_now authorization (EUVD-2025-19919)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Booking X Plugin up to 1.1.2 on WordPress. Affected by this issue is the function export_now of the component HTTP POST Request Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2025-6814. The attack may be launched remotely. There is no exploit available.
vuldb.com
Microsoft shuts down 3,000 email accounts created by North Korean IT workers
2 months 2 weeks ago
Microsoft said it has spent years monitoring North Korea’s campaign to get its citizens hired in IT roles at U.S. companies and recently saw changes in how the campaign operates.
CVE-2025-5953 | WP Human Resource Management Plugin up to 2.2.17 on WordPress AJAX ajax_insert_employee role authorization (EUVD-2025-19920)
2 months 2 weeks ago
A vulnerability classified as critical was found in WP Human Resource Management Plugin up to 2.2.17 on WordPress. Affected by this vulnerability is the function ajax_insert_employee of the component AJAX Handler. The manipulation of the argument role leads to missing authorization.
This vulnerability is known as CVE-2025-5953. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6586 | Download Plugin up to 2.2.8 on WordPress dpwap_plugin_locInstall unrestricted upload (EUVD-2025-19921)
2 months 2 weeks ago
A vulnerability classified as critical has been found in Download Plugin up to 2.2.8 on WordPress. Affected is the function dpwap_plugin_locInstall. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2025-6586. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5956 | WP Human Resource Management Plugin up to 2.2.17 on WordPress ajax_delete_employee delete authorization (EUVD-2025-19923)
2 months 2 weeks ago
A vulnerability was found in WP Human Resource Management Plugin up to 2.2.17 on WordPress. It has been rated as problematic. This issue affects the function ajax_delete_employee. The manipulation of the argument delete leads to missing authorization.
The identification of this vulnerability is CVE-2025-5956. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-50263 | Tenda AC6 15.03.05.16 fromSetRouteStatic list buffer overflow (EUVD-2025-19881)
2 months 2 weeks ago
A vulnerability was found in Tenda AC6 15.03.05.16. It has been declared as critical. This vulnerability affects the function fromSetRouteStatic. The manipulation of the argument list leads to buffer overflow.
This vulnerability was named CVE-2025-50263. The attack can be initiated remotely. There is no exploit available.
vuldb.com