-
Beware: Mobile Phishing Mimicking the USPS Is On the Rise
Researchers at Zimperium warn that a large phishing campaign is impersonating the US Postal Service (USPS) to target mobile devices with malicious PDF files. Go to Source
-
Your KnowBe4 Fresh Content Updates from January 2025
Check out the 25 new pieces of training content added in January, alongside the always fresh content update highlights, new features and events. Go to Source
-
CVE-2025-0804 – WordPress ClickWhale Link Manager Stored XSS
CVE ID : CVE-2025-0804 Published : Jan. 29, 2025, 4:15 a.m. | 2 hours, 46 minutes ago Description : The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to…
-
CVE-2024-12749 – WordPress Competition Form XSS Vulnerability
CVE ID : CVE-2024-12749 Published : Jan. 29, 2025, 6:15 a.m. | 45 minutes ago Description : The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. Severity:…
-
CVE-2025-23362 – Adobe EXIF Viewer Classic Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-23362 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed…
-
CVE-2025-0806 – Code-projects Job Recruitment Cross Site Scripting Vulnerability
CVE ID : CVE-2025-0806 Published : Jan. 29, 2025, 3:15 a.m. | 3 hours, 46 minutes ago Description : A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of the argument job_type leads to cross site scripting. The attack…
-
CVE-2025-0802 – SourceCodester Best Employee Management System Remote Improper Access Control Vulnerability
CVE ID : CVE-2025-0802 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls.…
-
CVE-2025-0803 – Codezips Gym Management System SQL Injection Vulnerability
CVE ID : CVE-2025-0803 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_new.php. The manipulation of the argument planid leads to sql injection.…
-
CVE-2025-0800 – SourceCodester Online Courseware Cross Site Scripting
CVE ID : CVE-2025-0800 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting.…