Latest CVE Feed
-
6.4
MEDIUMCVE-2025-5585
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it... Read more
Affected Products : siteorigin_widgets_bundle- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-36004
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious actor could cause user-controlled code to run with administrator privilege.... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
7.6
HIGHCVE-2025-0966
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6583
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /view-appointment.php. The manipulation of the argument viewid leads to sql injection. It is possible... Read more
Affected Products : best_salon_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6582
A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /edit-customer-detailed.php. The manipulation of the argument editid lea... Read more
Affected Products : best_salon_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6581
A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-customer.php. The manipulation of the argument name/email/mobilenum/gender/det... Read more
Affected Products : best_salon_management_system- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6580
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the component Login. The manipulation of the argument Username leads to sql injection. It is possible to launch th... Read more
Affected Products : best_salon_management_system- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
1.7
LOWCVE-2025-52884
RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repository contains Solidity verifier contracts, Steel EVM view call library, and supporting code. Prior to versions 2.1.1 and 2.2.0, the `S... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-52883
Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any other node of the mesh. This message will be displayed in... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-52572
Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the server by authorizin... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6579
A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /message_admin.php. The manipulation of the argument Message leads to sql injection. The attack may be ... Read more
Affected Products : car_rental_system- Published: Jun. 24, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6578
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_account.php. The manipulation of the argument admin_id leads to sql ... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-6557
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Lo... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-6556
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-6555
Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
4.2
MEDIUMCVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the... Read more
Affected Products : moodle- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-52888
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure t... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: XML External Entity
-
8.8
HIGHCVE-2025-52882
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Misconfiguration
-
4.2
MEDIUMCVE-2025-52880
Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has been discovered in versions 1.8.0 through 1.21.3 when serving EPUB resources, either directly from the API, or when reading using the epu... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2025-52571
Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is p... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication