King Addons for Elementor plugin (10,000+ sites) has two critical unauthenticated vulnerabilities enabling full site takeover. CVE-2025-6327: arbitrary file upload via exposed AJAX handler—attackers c…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#wordpress#elementor#rce#privilege-escalation#file-upload#cve-2025-6327#cve-2025-6325
Sophos CTU researchers reported active exploitation of a remote code execution flaw (CVE-2025-59287) in Microsoft WSUS. Attackers used a Base64-encoded PowerShell command to exfiltrate Active Director…
Category: Vulnerabilities / Exploitation / Microsoft
#windows#cve-2025-59287#rce#sophos#vulnerability
The RediShell RCE flaw (CVE-2025-49844) in Redis’s Lua scripting engine enables host-level remote code execution. Criminal IP researchers identified 8,500 exposed instances globally, with over 50% in …
Category: Vulnerabilities / Exploitation / Database
#redis#rce#lua#criminalip#cve-2025-49844
Security researchers have reported active exploitation of CVE-2025-59287 in Microsoft Windows Server Update Services (WSUS). The flaw allows unauthenticated remote code execution through deserializati…
Category: Vulnerabilities / Microsoft / Microsoft
#cve-2025-59287#microsoft#rce#advisory#wsus
A widespread exploitation campaign targets WordPress websites running outdated GutenKit and Hunk Companion plugins, leveraging CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972 to achieve remote code e…
Category: Threats / Web Security / CMS Exploits
#wordpress#rce#cms#cve#mass-attack
Microsoft's Security Update Guide details CVE-2025-59295, a Windows URL parsing vulnerability that can lead to remote code execution when a user interacts with a specially crafted link or file. The fl…
Category: Threat Alerts / Vulnerabilities & Exploits / Vendor Security Advisories
#microsoft#windows#cve-2025-59295#rce
Oracle has released its October 2025 Critical Patch Update (CPU), addressing multiple high-severity vulnerabilities across Oracle Database, Fusion Middleware, MySQL, and Java SE. The advisory highligh…
Category: Threat Alerts / Vulnerabilities & Exploits / Vendor Security Advisories
#CVE#patch#Oracle#critical update#RCE
Security researchers disclosed a serious remote code execution vulnerability in the Rust library tokio-tar, affecting major projects such as uv, testcontainers, and wasmCloud. The vulnerability stems …
Category: Threat Alerts / Vulnerabilities & Exploits / Open Source Supply Chain
#Rust#RCE#vulnerability#supply chain
Shadowserver reports more than 71,000 internet-exposed WatchGuard Fireware devices vulnerable to CVE-2025-9242, a critical (CVSS 9.8) out-of-bounds write in IKEv2 that can lead to unauthenticated remo…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#cve-2025-9242#watchguard#rce#ikev2
A critical out-of-bounds write vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Fireware’s IKEv2 VPN allows unauthenticated remote code execution on Firebox appliances. Attackers can exploit the …
Category: Vulnerabilities & Exploits / Network & Edge / Network & Edge
#watchguard#fireware#vpn#cve-2025-9242#rce
Git CVE-2025-48384 is a parsing vulnerability allowing malicious .gitmodules files to perform arbitrary file writes that lead to command execution when repositories are cloned recursively. CrowdStrike…
Category: Vulnerabilities & Exploits / Application Security / Application Security
#git#cve-2025-48384#hooks#rce#crowdstrike
Elastic disclosed CVE-2025-37729 (CVSS 9.1) in Elastic Cloud Enterprise (ECE) where Jinjava variable injection within deployment plans can trigger command execution on underlying hosts, with results v…
Category: Threat Alerts / Vulnerabilities & Exploits / Cloud & Orchestration
#elastic#ece#rce#jinjava
Two 7-Zip vulnerabilities (CVE-2025-11001, CVE-2025-11002) allow directory traversal via symbolic links in ZIP archives, enabling overwrite of arbitrary files and potential code execution when paired …
Category: Threat Alerts / Vulnerabilities & Exploits / Client Applications
#7zip#cve#rce#zip#symlink
A practitioner’s post details response to CVE-2025-49844 (CVSS 10.0) in Redis, referencing GHSA-4789-qfc9-5f9q. Mitigations included immediate ACL restrictions disabling EVAL/EVALSHA, upgrading from R…
Category: Threat Alerts / Vulnerabilities & Exploits / Databases & Caches
#redis#cve#acl#rce#ha