4.6

CVSS4.0

CVE-2025-48875 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed in a flesh-message when the data is deletedโ€ฆ

๐Ÿ“… Published: May 30, 2025, 6:26 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 7:54 p.m.

4.6

CVSS4.0

CVE-2025-48489 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been patched in version 1.8.180.

๐Ÿ“… Published: May 30, 2025, 6:18 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 7:56 p.m.

6

CVSS4.0

CVE-2025-48487 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability. This issue has been patched in version 1.8.180.

๐Ÿ“… Published: May 30, 2025, 6:17 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 7:57 p.m.

6.1

CVSS4.0

CVE-2025-48486 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of input validation and sanitization in both \Session::flash and __, allowing user input to be executed without proper filtering. This issue haโ€ฆ

๐Ÿ“… Published: May 30, 2025, 6:17 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 7:57 p.m.

6.1

CVSS4.0

CVE-2025-48485 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated user updates the profile of an arbitrary customer. โ€ฆ

๐Ÿ“… Published: May 30, 2025, 6:16 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 2:32 p.m.

9.1

CVSS3.1

CVE-2025-48865 - Fabio allows HTTP clients to manipulate custom headers it adds

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds HTTP headers like X-Forwarded-Host and X-Forโ€ฆ

๐Ÿ“… Published: May 30, 2025, 6:14 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 7:54 p.m.

8.6

CVSS4.0

CVE-2025-48492 - GetSimple CMS RCE in Edit component

GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to โ€ฆ

๐Ÿ“… Published: May 30, 2025, 6:13 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 7:56 p.m.

5.3

CVSS3.1

CVE-2025-48889 - Gradio Allows Unauthorized File Copy via Path Manipulation

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy anyโ€ฆ

๐Ÿ“… Published: May 30, 2025, 6:12 a.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 4:28 p.m.

6.1

CVSS3.1

CVE-2025-4429 - WordPress Gearside Developer Dashboard <= 1.0.72 - Reflected XSS

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

๐Ÿ“… Published: May 30, 2025, 6 a.m. ๐Ÿ”„ Last Modified: June 9, 2025, 8:30 p.m.

8.6

CVSS3.1

CVE-2025-41235 - CVE-2025-41235: Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies

Spring Cloud Gateway Server forwards the X-Forwarded-Forย and Forwardedย headers from untrusted proxies.

๐Ÿ“… Published: May 30, 2025, 5:57 a.m. ๐Ÿ”„ Last Modified: May 30, 2025, 4:31 p.m.
Total resulsts: 343975
Page 4701 of 34,398
ยซ previous page ยป next page
Filters