A vulnerability was found in Testimonial Slider and Showcase Pro Plugin up to 2.1.7 on WordPress. It has been rated as critical. The affected element is an unknown function. Performing manipulation results in file inclusion.
This vulnerability is cataloged as CVE-2025-32657. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Ninja Tables Pro Plugin up to 5.0.17 on WordPress. It has been rated as problematic. This vulnerability affects unknown code. Performing manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-39534. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical has been found in Insurance Plugin up to 3.5 on WordPress. This impacts an unknown function. This manipulation causes deserialization.
This vulnerability is handled as CVE-2025-31634. The attack can be initiated remotely. There is not any exploit available.
A vulnerability has been found in Solar Energy Theme up to 3.5 on WordPress and classified as critical. This affects an unknown part. This manipulation causes deserialization.
This vulnerability appears as CVE-2025-32283. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as critical has been found in Tablesome Table Premium Plugin up to 1.1.23 on WordPress. The impacted element is an unknown function. The manipulation results in missing authorization.
This vulnerability is identified as CVE-2025-30944. The attack can be executed remotely. There is not any exploit available.
A vulnerability described as problematic has been identified in WP Gmail SMTP Plugin up to 1.0.7 on WordPress. This affects an unknown function. Executing manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2025-53232. The attack can be launched remotely. No exploit exists.
A vulnerability classified as problematic has been found in AppExperts Plugin up to 1.4.5 on WordPress. This impacts an unknown function. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2025-53218. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in Search & Filter Plugin up to 1.2.17 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes cross-site request forgery.
This vulnerability is registered as CVE-2025-48099. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability described as critical has been identified in Oracle Database Server up to 19.28/21.19/23.9. Affected by this vulnerability is an unknown functionality of the component Java VM Component. The manipulation results in improper access controls.
This vulnerability was named CVE-2025-61881. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Oracle ZFS Storage Appliance Kit 8.8. The impacted element is an unknown function of the component Block Storage. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-62290. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
E-commerce security company Sansec has warned that threat actors have begun to exploit a recently disclosed security vulnerability in Adobe Commerce and Magento Open Source platforms, with more than 250 attack attempts recorded against multiple stores over the past 24 hours.
The vulnerability in question is CVE-2025-54236 (CVSS score: 9.1), a critical improper input validation flaw that could be
A vulnerability was found in Oracle PeopleSoft Enterprise PeopleTools 8.60/8.61/8.62. It has been rated as critical. Impacted is an unknown function of the component PIA Core Technology. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-53061. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in Oracle PeopleSoft Enterprise PeopleTools 8.60/8.61/8.62. This affects an unknown function of the component PIA Core Technology. Such manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2025-53055. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.9.4. It has been rated as critical. This affects an unknown function of the component Web Runtime SEC. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2025-53060. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Oracle JD Edwards EnterpriseOne Tools up to 9.2.9.4. This impacts an unknown function of the component Object And Environment Tech. Such manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2025-53056. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Oracle iStore up to 12.2.14. It has been classified as critical. The affected element is an unknown function of the component Shopping Cart. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-53041. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Motex Lanscope Endpoint Manager to its Known Exploited Vulnerabilities (KEV) catalog, stating it has been actively exploited in the wild.
The vulnerability, CVE-2025-61932 (CVSS v4 score: 9.3), impacts on-premises versions of Lanscope Endpoint Manager, specifically Client