Cybercriminals are auctioning off live email credentials, giving other criminals access to sensitive systems, confidential intelligence, and, potentially, a higher success rate than ever.
The US National Institute of Standards and Technology updated its Digital Identity Guidelines to match current threats. The document detailed technical recommendations as well as suggestions for organizations.
A vulnerability was found in projectworlds Travel Management System 1.0. It has been rated as critical. This vulnerability affects unknown code of the file /updatesubcategory.php. The manipulation of the argument t1/s1 leads to sql injection.
This vulnerability was named CVE-2025-9053. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in projectworlds Travel Management System 1.0. It has been declared as critical. This affects an unknown part of the file /updatepackage.php. The manipulation of the argument s1 leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-9052. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in projectworlds Travel Management System 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file /updatecategory.php. The manipulation of the argument t1 leads to sql injection.
This vulnerability is handled as CVE-2025-9051. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in projectworlds Travel Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /addcategory.php. The manipulation of the argument t1 leads to sql injection.
This vulnerability is known as CVE-2025-9050. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in projectworlds Visitor Management System 1.0 and classified as critical. Affected is an unknown function of the file /visitor_out.php. The manipulation of the argument rid leads to sql injection.
This vulnerability is traded as CVE-2025-9047. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-9046. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in Quttera Web Malware Scanner Plugin up to 3.5.1.41 on WordPress. This vulnerability affects the function RunExternalScan. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-8013. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic was found in Essential Addons for Elementor Plugin up to 6.2.2 on WordPress. This affects an unknown part. The manipulation of the argument data-gallery-items leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-8451. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical has been found in Bit Form builder Plugin up to 2.20.3/2.20.4 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-6679. The attack may be launched remotely. There is no exploit available.
A vulnerability described as problematic has been identified in Crocoblock JetElements for Elementor Plugin up to 2.7.9 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-55714. The attack can be launched remotely. There is no exploit available.
A vulnerability marked as problematic has been reported in CreativeThemes Blocksy Plugin up to 2.1.6 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-55713. It is possible to launch the attack remotely. There is no exploit available.