CVE Feed
- CVE-2025-12130 – WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 – Cross-Site Request Forgery to Vendor Product Deletion December 5, 2025
- CVE-2025-13684 – ARK Related Posts <= 2.19 – Cross-Site Request Forgery to Settings Update December 5, 2025
- CVE-2025-12374 – Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.39 – Authentication Bypass to Account Takeover December 5, 2025
- CVE-2025-12850 – My auctions allegro <= 3.6.32 – Unauthenticated SQL Injection via auction_id December 5, 2025
- CVE-2025-13515 – Nouri.sh Newsletter <= 1.0.1.3 – Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] December 5, 2025
- CVE-2025-12186 – Weekly Planner <= 1.0 – Authenticated (Admin+) Stored Cross-Site Scripting December 5, 2025
- CVE-2025-12354 – Live CSS Preview <= 2.0.0 – Missing Authorization to Authenticated (Subscriber+) Settings Update December 5, 2025
- CVE-2025-12355 – Payaza <= 0.3.8 – Missing Authorization to Unauthenticated Order Status Update December 5, 2025
- CVE-2025-12373 – Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.9 – Cross-Site Request Forgery To Plugin's Settings Modification December 5, 2025
- CVE-2025-12093 – Voidek Employee Portal <= 1.0.6 – Missing Authorization December 5, 2025
- CVE-2025-66270 – KDE Connect GSConnect Valent Device ID Correlation Vulnerability December 5, 2025
- CVE-2025-13622 – Jabbernotification <= 0.99-RC2 – Reflected Cross-Site Scripting via admin.php PATH_INFO December 5, 2025
- CVE-2025-13623 – Twitscription <= 0.1.1 – Reflected Cross-Site Scripting via admin.php PATH_INFO December 5, 2025
- CVE-2025-13625 – WP-SOS-Donate Donation Sidebar Plugin <= 0.9.2 – Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] December 5, 2025
- CVE-2025-32900 – KDE Connect Information Exposure Vulnerability December 5, 2025
- CVE-2025-13621 – dream gallery <= 1.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action December 5, 2025
- CVE-2025-13860 – Easy Jump Links Menus <= 1.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes December 5, 2025
- CVE-2025-12368 – Sermon Manager <= 2.30.0 – Authenticated (Contributor+) Stored Cross-Site Scripting December 5, 2025
- CVE-2025-12370 – Takeads <= 1.0.13 – Missing Authorization to Plugin Settings Deletion December 5, 2025
Microsoft Security
- Cybersecurity strategies to prioritize now​​ December 4, 2025In this article, Damon Becknel, Vice President and Deputy CISO for Regulated Industries at Microsoft, outlines four things to prioritize doing now. The post Cybersecurity strategies to prioritize now​​ appeared first on Microsoft Security Blog.Damon Becknel
- How to build forward-thinking cybersecurity teams for tomorrow December 2, 2025To secure the future, we must future-proof our cybersecurity talent and develop teams that are agile, innovative, and perpetually learning. The post How to build forward-thinking cybersecurity teams for tomorrow appeared first on Microsoft Security Blog.Ann Johnson
- Charting the future of SOC: Human and AI collaboration for better security November 25, 2025This blog shares our journey and insights from building autonomous AI agents for MDR operations and explores how the shift to a GenAI-powered SOC redefines collaboration between humans and AI. The post Charting the future of SOC: Human and AI collaboration for better security appeared first on Microsoft Security Blog.Microsoft Defender Experts
- Microsoft named a Leader in the Gartner® Magic Quadrant™ for Access Management for the ninth consecutive year November 21, 2025We’re happy to share that Microsoft has been recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for Access Management for the ninth consecutive year. The post Microsoft named a Leader in the Gartner® Magic Quadrant™ for Access Management for the ninth consecutive year appeared first on Microsoft Security Blog.Joy Chik
- ​​Ambient and autonomous security for the agentic era​​ November 18, 2025In the agentic era, security must be ambient and autonomous, like the AI it protects. This is our vision for security, where security becomes the core primitive. The post ​​Ambient and autonomous security for the agentic era​​ appeared first on Microsoft Security Blog.Vasu Jakkal



