Recent Advisories

Severity ID Title Vendor Product Date Type
Unknown ADV-3580

CVE-2025-4208 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function

Vulnerability Details Basic Information Title CVE-2025-4208 NEX-Forms – Ultimate Form Builder – Contact forms and much more

N/A N/A NEWS
Unknown ADV-3579

CVE-2025-3862 Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Vulnerability Details Basic Information Title CVE-2025-3862 Contest Gallery

N/A N/A NEWS
Unknown ADV-3578

CVE-2025-2806 tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'

Vulnerability Details Basic Information Title CVE-2025-2806 tagDiv Composer

N/A N/A NEWS
Unknown ADV-3577

CVE-2025-3506 Potentially senitive path exposed via unauthenticated http route

Vulnerability Details Basic Information Title CVE-2025-3506 Potentially senitive path exposed via unauthenticated http route Type cve Published 202...

N/A N/A NEWS
Unknown ADV-3576

MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware

Security Update News Update Information Title MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware Update ID THN:EE7B5FE...

N/A N/A NEWS
Unknown ADV-3575

CVE-2025-3758

Vulnerability Details Basic Information Title CVE-2025-3758 Type cve Published 2025-05-08T10:15:18 Last Seen 2025-05-08T10:23:27 CVSS Score 0.0 () ...

N/A N/A NEWS
Unknown ADV-3574

CVE-2025-41450

Vulnerability Details Basic Information Title CVE-2025-41450 Type cve Published 2025-05-08T10:15:18 Last Seen 2025-05-08T10:26:09 CVSS Score 8.2 (H...

N/A N/A NEWS
Unknown ADV-3573

CVE-2025-3759

Vulnerability Details Basic Information Title CVE-2025-3759 Type cve Published 2025-05-08T10:15:18 Last Seen 2025-05-08T10:23:27 CVSS Score 0.0 () ...

N/A N/A NEWS
Unknown ADV-3572

curl: CRLF Injection in `–proxy-header` allows extra HTTP headers (CWE-93)

Security Update News Update Information Title curl: CRLF Injection in `–proxy-header` allows extra HTTP headers (CWE-93) Update ID H1:3133379...

N/A N/A NEWS
Unknown ADV-3571

Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware

Security Update News Update Information Title Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware Update ID THN:EAF24074ABD3...

N/A N/A NEWS