0.0

CVE-2025-53499 - Unauthorized Inspection of Protected Variables in AbuseFilter

: Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki - AbuseFilter Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

📅 Published: July 7, 2025, 6:33 p.m. 🔄 Last Modified: July 7, 2025, 7:15 p.m.

4.8

CVSS4.0

CVE-2025-7140 - SourceCodester Best Salon Management System Update Staff Page edit-staff.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-staff.php of the component Update Staff Page. The manipulation of the argument Staff Name leads to cross site scripting. It is possibl…

📅 Published: July 7, 2025, 6:32 p.m. 🔄 Last Modified: July 7, 2025, 7:15 p.m.

0.0

CVE-2025-53495 - Unauthorized Disclosure of IP Reputation in AbuseFilter

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki - AbuseFilter Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

📅 Published: July 7, 2025, 6:30 p.m. 🔄 Last Modified: July 7, 2025, 7:15 p.m.

5.4

CVSS3.1

CVE-2025-53478 - CheckUser: Reflected Cross-Site Scripting (XSS) in Special:Investigate via unsanitized i18n messages

The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension: from 1.39.X before 1.39.13, from 1.42.X bef…

📅 Published: July 7, 2025, 6:16 p.m. 🔄 Last Modified: July 7, 2025, 9:15 p.m.

4.8

CVSS4.0

CVE-2025-7139 - SourceCodester Best Salon Management System Update Customer Details Page edit-customer-detailed.php…

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /panel/edit-customer-detailed.php of the component Update Customer Details Page. The manipulation of the argument Name leads to cros…

📅 Published: July 7, 2025, 6:02 p.m. 🔄 Last Modified: July 7, 2025, 7:15 p.m.

8.1

CVSS3.1

CVE-2025-53536 - Roo Code allows Potential Remote Code Execution via .vscode/settings.json

Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to the agent could write to VS Code settings files and trigger code execution. There were multiple ways to achieve that. One example is with th…

📅 Published: July 7, 2025, 5:57 p.m. 🔄 Last Modified: July 7, 2025, 6:15 p.m.

4.3

CVSS3.1

CVE-2025-20322 - Denial of Service (DoS) in Search Head Cluster through Cross-Site Request Forgery (CSRF) in Splunk …

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, an unauthenticated attacker could send a specially-crafted SPL search command that could trigger a rolling restart in the Search Head Cluster t…

📅 Published: July 7, 2025, 5:48 p.m. 🔄 Last Modified: July 7, 2025, 6:15 p.m.

4.3

CVSS3.1

CVE-2025-20323 - Missing Access Control of Saved Searches in the Splunk Archiver app

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver application. This is because of missing access controls in the saved…

📅 Published: July 7, 2025, 5:48 p.m. 🔄 Last Modified: July 7, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2025-20321 - Membership State Change in Splunk Search Head Cluster through a Cross-Site Request Forgery (CSRF) i…

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.114, and 9.2.2406.119, an unauthenticated attacker can send a specially-crafted SPL search that could change the membership state in a Splunk Search Head Cluster (SHC)…

📅 Published: July 7, 2025, 5:48 p.m. 🔄 Last Modified: July 7, 2025, 6:15 p.m.

3.1

CVSS3.1

CVE-2025-20325 - Sensitive Information Disclosure in the SHCConfig logging channel in Clustered Deployments in Splun…

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.113, and 9.2.2406.119, the software potentially exposes the search head cluster [splunk.secret](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-a…

📅 Published: July 7, 2025, 5:48 p.m. 🔄 Last Modified: July 7, 2025, 6:15 p.m.
Total resulsts: 300790
Page 8 of 30,079
« previous page » next page
Filters