NA - CVE-2025-52888 - Allure 2 is the version 2.x branch of Allure...
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior...
NA - CVE-2025-53021 - A session fixation vulnerability in Moodle 3.x...
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication...
NA - CVE-2025-6555 - Use after free in Animation in Google Chrome...
Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
NA - CVE-2025-6556 - Insufficient policy enforcement in Loader in...
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
NA - CVE-2025-6557 - Insufficient data validation in DevTools in...
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary...
High - CVE-2025-6578 - A vulnerability was found in code-projects...
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file...
High - CVE-2025-6579 - A vulnerability was found in code-projects Car...
A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /message_admin.php. The manipulation of the...
NA - CVE-2025-52572 - Hikka, a Telegram userbot, has vulnerability...
Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his...
NA - CVE-2025-52883 - Meshtastic-Android is an Android application...
Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any...
NA - CVE-2025-52884 - RISC Zero is a zero-knowledge verifiable...
RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repository contains Solidity verifier contracts, Steel EVM view call library, and...