4.8

CVSS4.0

CVE-2025-7144 - SourceCodester Best Salon Management System Admin Profile Page admin-profile.php cross site scriptiโ€ฆ

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /panel/admin-profile.php of the component Admin Profile Page. The manipulation of the argument Admin Name leads to cross site scriptinโ€ฆ

๐Ÿ“… Published: July 7, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 3:32 p.m.

4.8

CVSS4.0

CVE-2025-7143 - SourceCodester Best Salon Management System Update Tax Page edit-tax.php cross site scripting

A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/edit-tax.php of the component Update Tax Page. The manipulation of the argument Tax Name leads to cross site scripting. It is possible โ€ฆ

๐Ÿ“… Published: July 7, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 3:31 p.m.

4.2

CVSS3.1

CVE-2025-53543 - Kestra allows Stored XSS before 0.22

Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0.

๐Ÿ“… Published: July 7, 2025, 7:54 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-7142 - SourceCodester Best Salon Management System search-appointment.php cross site scripting

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /panel/search-appointment.php. The manipulation leads to cross site scripting. The attack may be launched remotelโ€ฆ

๐Ÿ“… Published: July 7, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 3:31 p.m.

8.7

CVSS4.0

CVE-2025-53540 - CSRF Vulnerability in Firmware Update Endpoints Allows Remote Code Execution

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Several OTA update examples and the HTTPUpdateServer implementation are vulnerable to Cross-Site Request Forgery (CSRF). The update endpoints accept POST requests for firmware uploaโ€ฆ

๐Ÿ“… Published: July 7, 2025, 7:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-53539 - ReDoS in fastapi-guard's penetration attempts detector

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. fastapi-guard's penetration attempts detection uses regex to scan incoming requests. However, some of the regex patterns used in detection are extremely inefficienโ€ฆ

๐Ÿ“… Published: July 7, 2025, 7:16 p.m. ๐Ÿ”„ Last Modified: Dec. 31, 2025, 5:05 p.m.

5.4

CVSS3.1

CVE-2025-53496 - Stored XSS in MediaSearch

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MediaSearch Extension allows Stored XSS.This issue affects Mediawiki - MediaSearch Extension: from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

๐Ÿ“… Published: July 7, 2025, 7:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-7141 - SourceCodester Best Salon Management System Update Staff Page edit_plan.php cross site scripting

A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /panel/edit_plan.php of the component Update Staff Page. The manipulation leads to cross site scripting. The attack can be lโ€ฆ

๐Ÿ“… Published: July 7, 2025, 7:02 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 5:24 p.m.

6.1

CVSS3.1

CVE-2025-6044 -

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture featurโ€ฆ

๐Ÿ“… Published: July 7, 2025, 6:58 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 3:54 p.m.

6.1

CVSS3.1

CVE-2025-53488 - Stored XSS in WikiHiero

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiHiero Extension allows Stored XSS.This issue affects Mediawiki - WikiHiero Extension: from 1.43.X before 1.43.2.

๐Ÿ“… Published: July 7, 2025, 6:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4759 of 34,919
ยซ previous page ยป next page
Filters