5.1

CVSS4.0

CVE-2025-41406 -

Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary script may be executed on the web browser of the moderator user.

πŸ“… Published: May 30, 2025, 6:36 a.m. πŸ”„ Last Modified: June 4, 2025, 7:58 p.m.

7.1

CVSS4.0

CVE-2025-41385 -

An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged-in administrative user.

πŸ“… Published: May 30, 2025, 6:35 a.m. πŸ”„ Last Modified: June 4, 2025, 7:58 p.m.

8.1

CVSS3.1

CVE-2025-48936 - ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection

Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset conf…

πŸ“… Published: May 30, 2025, 6:30 a.m. πŸ”„ Last Modified: June 4, 2025, 6:31 p.m.

4.6

CVSS4.0

CVE-2025-48488 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripting (XSS) vulnerability. This issue has been patch…

πŸ“… Published: May 30, 2025, 6:30 a.m. πŸ”„ Last Modified: June 4, 2025, 7:57 p.m.

5.1

CVSS4.0

CVE-2025-48880 - FreeScout has Race Condition When Deleting Users

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is the the possibility of a race condition occurring. This issue has been patched in version 1.8.181.

πŸ“… Published: May 30, 2025, 6:27 a.m. πŸ”„ Last Modified: June 4, 2025, 6:32 p.m.

4.6

CVSS4.0

CVE-2025-48875 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed in a flesh-message when the data is deleted…

πŸ“… Published: May 30, 2025, 6:26 a.m. πŸ”„ Last Modified: June 4, 2025, 7:54 p.m.

4.6

CVSS4.0

CVE-2025-48489 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been patched in version 1.8.180.

πŸ“… Published: May 30, 2025, 6:18 a.m. πŸ”„ Last Modified: June 4, 2025, 7:56 p.m.

6

CVSS4.0

CVE-2025-48487 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability. This issue has been patched in version 1.8.180.

πŸ“… Published: May 30, 2025, 6:17 a.m. πŸ”„ Last Modified: June 4, 2025, 7:57 p.m.

6.1

CVSS4.0

CVE-2025-48486 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of input validation and sanitization in both \Session::flash and __, allowing user input to be executed without proper filtering. This issue ha…

πŸ“… Published: May 30, 2025, 6:17 a.m. πŸ”„ Last Modified: June 4, 2025, 7:57 p.m.

6.1

CVSS4.0

CVE-2025-48485 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated user updates the profile of an arbitrary customer. …

πŸ“… Published: May 30, 2025, 6:16 a.m. πŸ”„ Last Modified: June 4, 2025, 2:32 p.m.
Total resulsts: 343970
Page 4700 of 34,397
Β« previous page Β» next page
Filters