Aggregator
美国20州起诉卫生部:反对将医保数据共享给移民执法机构
8 months ago
安全客
Microsoft investigates ongoing SharePoint Online access issues
8 months ago
Microsoft is investigating an ongoing incident causing intermittent issues for users attempting to access SharePoint Online sites. [...]
Sergiu Gatlan
Alleged Data Sale of doValue S.p.A.
8 months ago
Alleged Data Sale of doValue S.p.A.
Dark Web Informer - Cyber Threat Intelligence
Wing FTP Server 曝CVSS 10.0 远程代码执行漏洞(CVE-2025-47812),可实现完全控制,PoC 已公开
8 months ago
安全客
Interpol identifies West Africa as potential new hotspot for cybercrime compounds
8 months ago
Interpol said it analyzed five years of data about the illicit industry, which relies on human trafficking to staff up centers with people who are forced to conduct investment fraud, romance scams and other schemes.
CVE-2025-6463:Forminator 插件曝高危任意文件删除漏洞,超 60 万 WordPress 网站恐遭远程接管
8 months ago
安全客
360亮相全球数字经济大会,智能体涌现,安全运营跃升
8 months ago
安全客
Кто держит минералы — держит мир за горло. Но 4 страны решили сказать Китаю: стоп, хватит
8 months ago
«Квад» начинает борьбу за независимость электромобилей и роботов.
Drupal security advisory (AV25-389)
8 months ago
Canadian Centre for Cyber Security
Apache Tomcat and Camel Vulnerabilities Actively Targeted in Cyberattacks
8 months ago
The Apache Foundation disclosed several critical vulnerabilities affecting two of its widely used software platforms, Apache Tomcat and Apache Camel, sparking immediate concern among cybersecurity experts and organizations worldwide. Apache Tomcat, a popular platform for running Java-based web applications, was found to have a severe flaw identified as CVE-2025-24813. This vulnerability, impacting versions 9.0.0.M1 to […]
The post Apache Tomcat and Camel Vulnerabilities Actively Targeted in Cyberattacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
CVE-2025-6041 | yContributors Plugin up to 0.5 on WordPress Setting cross-site request forgery (EUVD-2025-19925)
8 months ago
A vulnerability was found in yContributors Plugin up to 0.5 on WordPress and classified as problematic. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-6041. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5933 | RD Contacto Plugin up to 1.4 on WordPress Setting rdWappUpdateData cross-site request forgery (EUVD-2025-19928)
8 months ago
A vulnerability has been found in RD Contacto Plugin up to 1.4 on WordPress and classified as problematic. Affected by this vulnerability is the function rdWappUpdateData of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-5933. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6039 | ProcessingJS Plugin up to 1.2.2 on WordPress pjs4wp cross site scripting (EUVD-2025-19914)
8 months ago
A vulnerability, which was classified as problematic, was found in ProcessingJS Plugin up to 1.2.2 on WordPress. Affected is the function pjs4wp. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-6039. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5924 | WP Firebase Push Notification Plugin up to 1.2.0 on WordPress wfpn_brodcast_notification_message cross-site request forgery (EUVD-2025-19916)
8 months ago
A vulnerability, which was classified as problematic, has been found in WP Firebase Push Notification Plugin up to 1.2.0 on WordPress. This issue affects the function wfpn_brodcast_notification_message. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-5924. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-7046 | Portfolio for Elementor & Image Gallery Plugin up to 3.2.0/3.2.1 on WordPress cross site scripting (EUVD-2025-19927)
8 months ago
A vulnerability classified as problematic was found in Portfolio for Elementor & Image Gallery Plugin up to 3.2.0/3.2.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-7046. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6787 | Smart Docs Plugin up to 1.1.0 on WordPress Shortcode smartdocs_search cross site scripting (EUVD-2025-19918)
8 months ago
A vulnerability classified as problematic has been found in Smart Docs Plugin up to 1.1.0 on WordPress. This affects the function smartdocs_search of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-6787. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6238 | AI Engine Plugin 2.8.4/2.8.5 on WordPress Meow_MWAI_Labs_OAuth redirect_uri (EUVD-2025-19924)
8 months ago
A vulnerability was found in AI Engine Plugin 2.8.4/2.8.5 on WordPress. It has been rated as problematic. Affected by this issue is the function Meow_MWAI_Labs_OAuth. The manipulation of the argument redirect_uri leads to open redirect.
This vulnerability is handled as CVE-2025-6238. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-6729 | PayMaster for WooCommerce Plugin up to 0.4.31 on WordPress wp_ajax_paym_status server-side request forgery (EUVD-2025-19922)
8 months ago
A vulnerability was found in PayMaster for WooCommerce Plugin up to 0.4.31 on WordPress. It has been declared as critical. Affected by this vulnerability is the function wp_ajax_paym_status. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2025-6729. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6786 | DocCheck Login Plugin up to 1.1.5 on WordPress improper authentication (EUVD-2025-19929)
8 months ago
A vulnerability was found in DocCheck Login Plugin up to 1.1.5 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6786. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com