Aggregator
CVE-2025-9991 | Tiny Bootstrap Elements Light Plugin up to 4.3.34 on WordPress Language file inclusion (EUVD-2025-31682)
CVE-2025-9762 | Post by Email Plugin up to 1.0.4b on WordPress save_attachments unrestricted upload (EUVD-2025-31690)
CVE-2025-9993 | Bei Fen Plugin up to 1.4.2/7.1 on WordPress task file inclusion (EUVD-2025-31692)
CVE-2025-8566 | GutenBee Plugin up to 2.18.0 on WordPress cross site scripting (EUVD-2025-31699)
CVE-2025-8624 | Nexa Blocks Plugin up to 1.1.0 on WordPress Google Maps Widget cross site scripting (EUVD-2025-31687)
CVE-2025-8877 | AffiliateWP Plugin up to 2.28.2 on WordPress ajax_get_affiliate_id_from_login sql injection (EUVD-2025-31707)
CVE-2025-8623 | WeedMaps Menu Plugin up to 1.2.0 on WordPress Shortcode weedmaps_menu cross site scripting (EUVD-2025-31689)
CVE-2025-8608 | Mihdan Plugin up to 1.6.11 on WordPress Block Attribute cross site scripting (EUVD-2025-31680)
CVE-2025-8777 | Planetcalc Plugin up to 2.2 on WordPress Language cross site scripting (EUVD-2025-31675)
CVE-2025-9946 | LockerPress Plugin up to 1.0 on WordPress Setting cross-site request forgery (EUVD-2025-31677)
CVE-2025-9852 | Yoga Schedule Momoyoga Plugin up to 2.9.0 on WordPress Shortcode momoyoga-schedule cross site scripting (EUVD-2025-31693)
CVE-2025-9948 | Chat by Chatwee Plugin up to 2.1.3 on WordPress Setting cross-site request forgery (EUVD-2025-31684)
CVE-2025-6815 | LatePoint Plugin up to 5.1.94 on WordPress cross site scripting (EUVD-2025-31705)
CVE-2025-7052 | LatePoint Plugin up to 5.1.94 on WordPress change_password cross-site request forgery (EUVD-2025-31702)
CVE-2025-59954 | KnowageLabs Knowage-Server up to 8.1.26 org.apache.commons.jxpath.JXPathContext MetaService.java code injection
CVE-2025-61584 | serverless-dns up to 0.1.30 command injection
Linux 6.17 Released With Fix for use-after-free Vulnerabilities
Linux Torvalds has announced the release of Linux Kernel 6.17, a new version focused on stability and incremental improvements rather than groundbreaking features. The update brings a host of bug fixes, security enhancements, and driver updates across various subsystems. In his release message, Torvalds described the final week of development as having “no huge surprises,” […]
The post Linux 6.17 Released With Fix for use-after-free Vulnerabilities appeared first on Cyber Security News.
Hackers Use Cellular Router API to Send Malicious SMS with Weaponized Links
The monitoring and analysis of vulnerability exploitations are among the primary responsibilities of Sekoia.io’s Threat Detection & Research (TDR) team. Using honeypots, the team monitors traffic targeting edge devices and internet-facing applications. On 22 July 2025, suspicious network traces appeared in our honeypots, reveals that a cellular router’s API was exploited to deliver smishing campaigns […]
The post Hackers Use Cellular Router API to Send Malicious SMS with Weaponized Links appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.