CVE-2025-2476 - Critical “Use-after-free” in Lens allows Remote Attack on Google Chrome (prior to 134..6998.117)
Google Chrome has always been one of the most popular web browsers, but with popularity comes attention from attackers. Recently, a critical “use-after-free” vulnerability (CVE-2025-2476)
CVE-2025-29926 - How Unauthenticated Users Can Take Over XWiki Farms via the WikiManager REST API
CVE-2025-29926 is a critical security vulnerability affecting the XWiki Platform's WikiManager REST API. It allows anyone with network access to exploit this API
CVE-2025-29924 - XWiki SubWiki Privacy Flaw Exposes Private Pages via REST API
Summary:
A new vulnerability, CVE-2025-29924, has been found in XWiki Platform, a popular open-source wiki system. Before versions 15.10.14, 16.4.6, and
CVE-2025-30197 - Unmasked API Key Exposure in Jenkins Zoho QEngine Plugin – Exploit Details & Remediation
A new vulnerability, CVE-2025-30197, has been discovered in the Jenkins Zoho QEngine Plugin, affecting versions up to and including 1..29.vfa_cc23396502. This flaw
CVE-2025-30154 - Major Reviewdog GitHub Action Supply Chain Compromise – Full Timeline, Exploit Analysis, and Mitigation
---
On March 11, 2025, a critical security incident struck the open source developer world: the popular reviewdog/action-setup GitHub Action was compromised, putting secrets
Episode
00:00:00
00:00:00