Abhijeet Kumawat, a cybersecurity enthusiast and bug bounty hunter, shares insights in his series "Bug Bounty from Scratch," emphasizing HTTP as a key tool in ethical hacking. He explains GET requests and aims to guide newcomers into the field.
A vulnerability classified as problematic has been found in QEMU. Affected is the function uefi_vars_write of the file hw/uefi/var-service-core.c of the component uefi. Performing manipulation results in information disclosure.
This vulnerability was named CVE-2025-8860. The attack needs to be approached within the local network. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
A vulnerability described as critical has been identified in Custom Query Shortcode Plugin up to 0.4.0 on WordPress. This impacts an unknown function. Such manipulation of the argument lens leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-8562. The attack can be launched remotely. No exploit exists.