Aggregator
Microsoft Outlook’s New Two-Click View for Encrypted Emails Protects You From Accidental Exposure
8 months 2 weeks ago
Microsoft is set to launch a significant security enhancement for Outlook users across multiple platforms. Starting April 2025, the company will roll out a new two-click verification feature for encrypted emails, requiring users to confirm their intent to access sensitive content explicitly. This update aims to reduce accidental exposure of confidential information, particularly in public […]
The post Microsoft Outlook’s New Two-Click View for Encrypted Emails Protects You From Accidental Exposure appeared first on Cyber Security News.
Guru Baran
美国CISA警告 SinoTrack GPS 跟踪器存在远程控制漏洞
8 months 2 weeks ago
安全客
Paragon spyware activity found on more journalists’ devices
8 months 2 weeks ago
Two European journalists were among the people recently notified by Apple that they had been targeted with spyware by Paragon, according to a report from the Citizen Lab, with one device showing signs of a full infection.
CVE-2024-56158 | xwiki-platform up to 15.10.15/16.4.6/16.10.1 DBMS_XMLGEN/DBMS_XMLQUERY sql injection (EUVD-2024-54677)
8 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in xwiki-platform up to 15.10.15/16.4.6/16.10.1. Affected by this issue is the function DBMS_XMLGEN/DBMS_XMLQUERY. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-56158. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5926 | Link Shield Plugin up to 0.5.4 on WordPress Setting link_shield_menu_options cross-site request forgery (EUVD-2025-18237)
8 months 2 weeks ago
A vulnerability classified as problematic was found in Link Shield Plugin up to 0.5.4 on WordPress. Affected by this vulnerability is the function link_shield_menu_options of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-5926. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5928 | WP Sliding Login Dashboard Panel Plugin up to 2.1.1 on WordPress Setting wp_sliding_panel_user_options cross-site request forgery (EUVD-2025-18229)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in WP Sliding Login Dashboard Panel Plugin up to 2.1.1 on WordPress. Affected is the function wp_sliding_panel_user_options of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-5928. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5938 | Digital Marketing and Agency Templates Addons for Elementor Plugin import_templates cross-site request forgery (EUVD-2025-18230)
8 months 2 weeks ago
A vulnerability was found in Digital Marketing and Agency Templates Addons for Elementor Plugin up to 1.1.1 on WordPress. It has been rated as problematic. This issue affects the function import_templates. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-5938. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-5123 | Contact Us Page Plugin up to 3.7.4 on WordPress style cross site scripting (EUVD-2025-18231)
8 months 2 weeks ago
A vulnerability was found in Contact Us Page Plugin up to 3.7.4 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument style leads to cross site scripting.
This vulnerability was named CVE-2025-5123. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-5939 | Telegram for WP Plugin up to 1.6.1 on WordPress Setting cross site scripting (EUVD-2025-18232)
8 months 2 weeks ago
A vulnerability was found in Telegram for WP Plugin up to 1.6.1 on WordPress. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5939. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5930 | WP2HTML Plugin up to 1.0.2 on WordPress Setting save cross-site request forgery (EUVD-2025-18235)
8 months 2 weeks ago
A vulnerability has been found in WP2HTML Plugin up to 1.0.2 on WordPress and classified as problematic. Affected by this vulnerability is the function Save of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-5930. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5233 | Color Palette Plugin up to 4.3.2 on WordPress hex cross site scripting (EUVD-2025-18234)
8 months 2 weeks ago
A vulnerability was found in Color Palette Plugin up to 4.3.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument hex leads to cross site scripting.
This vulnerability is handled as CVE-2025-5233. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-4586 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmcalendarview cross site scripting (EUVD-2025-18233)
8 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in IRM Newsroom Plugin up to 1.2.17 on WordPress. Affected is the function irmcalendarview of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-4586. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-4585 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmflat cross site scripting (EUVD-2025-18241)
8 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in IRM Newsroom Plugin up to 1.2.17 on WordPress. This issue affects the function irmflat of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-4585. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Play
8 months 2 weeks ago
You must login to view this content
cohenido
CVE-2025-4584 | IRM Newsroom Plugin up to 1.2.17 on WordPress Shortcode irmeventlist cross site scripting (EUVD-2025-18239)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in IRM Newsroom Plugin up to 1.2.17 on WordPress. This affects the function irmeventlist of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4584. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5282 | WP Travel Engine Plugin up to 6.5.1 on WordPress delete_package authorization (EUVD-2025-18242)
8 months 2 weeks ago
A vulnerability classified as critical was found in WP Travel Engine Plugin up to 6.5.1 on WordPress. This vulnerability affects the function delete_package. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-5282. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-32303 | WPCHURCH Plugin up to 2.7.0 on WordPress sql injection
8 months 2 weeks ago
A vulnerability was found in WPCHURCH Plugin up to 2.7.0 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2025-32303. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-47569 | WooCommerce Ultimate Gift Card Plugin up to 2.8.10 on WordPress sql injection
8 months 2 weeks ago
A vulnerability was found in WooCommerce Ultimate Gift Card Plugin up to 2.8.10 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-47569. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5841 | ACF Onyx Poll Plugin up to 1.1.8 on WordPress Class cross site scripting (EUVD-2025-18236)
8 months 2 weeks ago
A vulnerability was found in ACF Onyx Poll Plugin up to 1.1.8 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument Class leads to cross site scripting.
This vulnerability is traded as CVE-2025-5841. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com