5.7

CVSS3.1

CVE-2024-57708 -

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.

๐Ÿ“… Published: June 25, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-6582 - SourceCodester Best Salon Management System edit-customer-detailed.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /edit-customer-detailed.php. The manipulation of the argument editid leads to sql injection. The attack may be launcโ€ฆ

๐Ÿ“… Published: June 24, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 5:04 p.m.

5.3

CVSS4.0

CVE-2025-6581 - SourceCodester Best Salon Management System add-customer.php sql injection

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-customer.php. The manipulation of the argument name/email/mobilenum/gender/details/dob/marriage_date leads to sql injectioโ€ฆ

๐Ÿ“… Published: June 24, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 5:11 p.m.

6.9

CVSS4.0

CVE-2025-6580 - SourceCodester Best Salon Management System Login sql injection

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the component Login. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been discโ€ฆ

๐Ÿ“… Published: June 24, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 5:13 p.m.

1.7

CVSS4.0

CVE-2025-52884 - risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steeโ€ฆ

RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repository contains Solidity verifier contracts, Steel EVM view call library, and supporting code. Prior to versions 2.1.1 and 2.2.0, the `Steel.validateCommitment` Solidity library fuโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8:20 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-52883 - Meshtastic-Android vulnerable to forged DMs with no PKC showing up as encrypted

Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any other node of the mesh. This message will be displayed in the same chat that the victim normally commโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-52572 - Hikka vulnerable to RCE through dangling web interface

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the server by authorizing in the dangling web interface. 2. Web inteโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8:10 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.7

CVSS3.1

CVE-2025-52571 - Hikka vulnerable to RCE through edits in a channel

Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2. No known workaroundโ€ฆ

๐Ÿ“… Published: June 24, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-6557 -

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: June 24, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.4

CVSS3.1

CVE-2025-6556 -

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: June 24, 2025, 8:03 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.
Total resulsts: 349182
Page 4898 of 34,919
ยซ previous page ยป next page
Filters