9.7

CVSS3.1

CVE-2025-52571 - Hikka vulnerable to RCE through edits in a channel

Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2. No known workaroundโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 26, 2025, 6:58 p.m.

5.4

CVSS3.1

CVE-2025-6557 -

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: June 24, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.4

CVSS3.1

CVE-2025-6556 -

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: June 24, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.4

CVSS3.1

CVE-2025-6555 -

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: June 24, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS4.0

CVE-2025-52882 - Claude Code IDE extensions allow websocket connections from arbitrary origins

Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages.โ€ฆ

๐Ÿ“… Published: June 24, 2025, 8:01 p.m. ๐Ÿ”„ Last Modified: June 26, 2025, 6:58 p.m.

6.9

CVSS4.0

CVE-2025-6579 - code-projects Car Rental System message_admin.php sql injection

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /message_admin.php. The manipulation of the argument Message leads to sql injection. The attack may be initiated remotely. The exploit has been disโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8 p.m. ๐Ÿ”„ Last Modified: July 11, 2025, 3:52 p.m.

6.9

CVSS4.0

CVE-2025-6578 - code-projects Simple Online Hotel Reservation System delete_account.php sql injection

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_account.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8 p.m. ๐Ÿ”„ Last Modified: July 11, 2025, 3:53 p.m.

4.2

CVSS3.1

CVE-2025-52880 - Komga Vulnerable to Arbitrary Code Execution via Crafted EPUB File

Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has been discovered in versions 1.8.0 through 1.21.3 when serving EPUB resources, either directly from the API, or when reading using the epub reader. The vulnerability lets an attackerโ€ฆ

๐Ÿ“… Published: June 24, 2025, 7:56 p.m. ๐Ÿ”„ Last Modified: June 26, 2025, 6:58 p.m.

7.2

CVSS4.0

CVE-2025-52471 - ESP-NOW Integer Underflow Vulnerability Advisory

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP Wi-Fi component of versions 5.4.1, 5.3.3, 5.2.5, and 5.1.6 of the ESP-IDF framework. This issue stems from insufficieโ€ฆ

๐Ÿ“… Published: June 24, 2025, 7:53 p.m. ๐Ÿ”„ Last Modified: Jan. 22, 2026, 4:05 p.m.

7.5

CVSS3.1

CVE-2025-52888 - Allure 2's xunit-xml-plugin Vulnerable to Improper XXE Restriction

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (`DocumentBuilderFactory`) andโ€ฆ

๐Ÿ“… Published: June 24, 2025, 7:45 p.m. ๐Ÿ”„ Last Modified: June 26, 2025, 6:58 p.m.
Total resulsts: 343921
Page 4373 of 34,393
ยซ previous page ยป next page
Filters