6.9

CVSS4.0

CVE-2025-6580 - SourceCodester Best Salon Management System Login sql injection

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the component Login. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disc…

πŸ“… Published: June 24, 2025, 9:31 p.m. πŸ”„ Last Modified: July 2, 2025, 5:13 p.m.

1.7

CVSS4.0

CVE-2025-52884 - risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Stee…

RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repository contains Solidity verifier contracts, Steel EVM view call library, and supporting code. Prior to versions 2.1.1 and 2.2.0, the `Steel.validateCommitment` Solidity library fu…

πŸ“… Published: June 24, 2025, 8:20 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:48 a.m.

5.3

CVSS3.1

CVE-2025-52883 - Meshtastic-Android vulnerable to forged DMs with no PKC showing up as encrypted

Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any other node of the mesh. This message will be displayed in the same chat that the victim normally comm…

πŸ“… Published: June 24, 2025, 8:12 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

10

CVSS3.1

CVE-2025-52572 - Hikka vulnerable to RCE through dangling web interface

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the server by authorizing in the dangling web interface. 2. Web inte…

πŸ“… Published: June 24, 2025, 8:10 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 5:22 p.m.

9.7

CVSS3.1

CVE-2025-52571 - Hikka vulnerable to RCE through edits in a channel

Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2. No known workaround…

πŸ“… Published: June 24, 2025, 8:07 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

5.4

CVSS3.1

CVE-2025-6557 -

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: June 24, 2025, 8:03 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.4

CVSS3.1

CVE-2025-6556 -

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: June 24, 2025, 8:03 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.4

CVSS3.1

CVE-2025-6555 -

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: June 24, 2025, 8:03 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS4.0

CVE-2025-52882 - Claude Code IDE extensions allow websocket connections from arbitrary origins

Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages.…

πŸ“… Published: June 24, 2025, 8:01 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

6.9

CVSS4.0

CVE-2025-6579 - code-projects Car Rental System message_admin.php sql injection

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /message_admin.php. The manipulation of the argument Message leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: June 24, 2025, 8 p.m. πŸ”„ Last Modified: July 11, 2025, 3:52 p.m.
Total resulsts: 343825
Page 4363 of 34,383
Β« previous page Β» next page
Filters