Aggregator
CVE-2025-46450 | x000x occupancyplan Plugin up to 1.0.3.0 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability has been found in x000x occupancyplan Plugin up to 1.0.3.0 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-46450. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-46442 | Casey Johnson Loan Calculator Plugin up to 1.3 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Casey Johnson Loan Calculator Plugin up to 1.3 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-46442. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-46439 | Vladimir Prelovac Plugin Central Plugin up to 2.5.1 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Vladimir Prelovac Plugin Central Plugin up to 2.5.1 on WordPress. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-46439. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46435 | Yash Binani Time Based Greeting Plugin up to 2.2.2 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability classified as problematic was found in Yash Binani Time Based Greeting Plugin up to 2.2.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-46435. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Lynx
10 months 3 weeks ago
cohenido
NFC-Powered Android Malware Enables Instant Cash-Outs
10 months 3 weeks ago
Researchers at security vendor Cleafy detailed a malware known as "SuperCard X" that uses the NFC reader on a victim's own phone to steal credit card funds instantly.
Alexander Culafi, Senior News Writer, Dark Reading
SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Remote Code Execution via File Upload Flaw
10 months 3 weeks ago
SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Remote Code Execution via File Upload Flaw
Dark Web Informer - Cyber Threat Intelligence
Lazarus hackers breach six companies in watering hole attacks
10 months 3 weeks ago
In a recent espionage campaign, the infamous North Korean threat group Lazarus targeted multiple organizations in the software, IT, finance, and telecommunications sectors in South Korea. [...]
Bill Toulas
Gig-Work Platforms at Risk for Data Breaches, Fraud, Account Takeovers
10 months 3 weeks ago
Fraudsters are targeting high-turnover workforces and compromising accounts that are associated with frequent payouts.
Tatiana Walk-Morris
Microsoft fixes machine learning bug flagging Adobe emails as spam
10 months 3 weeks ago
Microsoft says it mitigated a known issue in one of its machine learning (ML) models that mistakenly flagged Adobe emails in Exchange Online as spam. [...]
Sergiu Gatlan
BSidesLV24 – Ground Truth – What Do We Learn When We Scan The Internet Every Hour?
10 months 3 weeks ago
Author/Presenter: Ariana Mirian
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – Ground Truth – What Do We Learn When We Scan The Internet Every Hour? appeared first on Security Boulevard.
Marc Handelman
Хочешь стать сильнее, увереннее и «успешнее»? Маносфера уже готова продать тебе рецепт выгорания под видом мужества
10 months 3 weeks ago
Маносфера — это не подземелье интернета, это зеркало общества, в котором каждый из нас увидит что-то своё, если всмотрится.
CVE-2025-46452 | Olav Kolbu Google News Plugin up to 2.5.1 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability classified as problematic has been found in Olav Kolbu Google News Plugin up to 2.5.1 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-46452. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-46506 | Lora77 WpZon Plugin up to 1.3 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability was found in Lora77 WpZon Plugin up to 1.3 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-46506. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-46462 | Trân Minh-Quân WPVN Plugin up to 0.7.8 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability was found in Trân Minh-Quân WPVN Plugin up to 0.7.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-46462. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-46436 | Sebastian Echeverry SCSS-Library Plugin up to 0.4.1 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability was found in Sebastian Echeverry SCSS-Library Plugin up to 0.4.1 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-46436. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-46511 | Derek Springer BeerXML Shortcode Plugin up to 0.71 on WordPress server-side request forgery
10 months 3 weeks ago
A vulnerability was found in Derek Springer BeerXML Shortcode Plugin up to 0.71 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2025-46511. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46443 | Adam Pery Animate Plugin up to 0.5 on WordPress server-side request forgery
10 months 3 weeks ago
A vulnerability has been found in Adam Pery Animate Plugin up to 0.5 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-46443. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46513 | Codebangers All in One Time Clock Lite Plugin up to 1.3.324 on WordPress cross-site request forgery
10 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Codebangers All in One Time Clock Lite Plugin up to 1.3.324 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-46513. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com