6.1

CVSS4.0

CVE-2025-48485 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated user updates the profile of an arbitrary customer. …

📅 Published: May 30, 2025, 6:16 a.m. 🔄 Last Modified: June 4, 2025, 2:32 p.m.

9.1

CVSS3.1

CVE-2025-48865 - Fabio allows HTTP clients to manipulate custom headers it adds

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds HTTP headers like X-Forwarded-Host and X-For…

📅 Published: May 30, 2025, 6:14 a.m. 🔄 Last Modified: June 4, 2025, 7:54 p.m.

8.6

CVSS4.0

CVE-2025-48492 - GetSimple CMS RCE in Edit component

GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to …

📅 Published: May 30, 2025, 6:13 a.m. 🔄 Last Modified: June 4, 2025, 7:56 p.m.

5.3

CVSS3.1

CVE-2025-48889 - Gradio Allows Unauthorized File Copy via Path Manipulation

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy any…

📅 Published: May 30, 2025, 6:12 a.m. 🔄 Last Modified: Aug. 26, 2025, 4:28 p.m.

6.1

CVSS3.1

CVE-2025-4429 - WordPress Gearside Developer Dashboard <= 1.0.72 - Reflected XSS

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

📅 Published: May 30, 2025, 6 a.m. 🔄 Last Modified: June 9, 2025, 8:30 p.m.

8.6

CVSS3.1

CVE-2025-41235 - CVE-2025-41235: Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.

📅 Published: May 30, 2025, 5:57 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-48490 - Laravel Rest Api has a Search Validation Bypass

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, an…

📅 Published: May 30, 2025, 5:27 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-4659 - Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.4…

The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web applicatio…

📅 Published: May 30, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2025-5259 - Minimal Share Buttons <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via align…

The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level ac…

📅 Published: May 30, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 8:45 p.m.

8.3

CVSS3.1

CVE-2025-48881 - Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthori…

Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all objects for which an object-management configuration exists can be listed, viewed, edited, created or deleted by unauthorised users. If object…

📅 Published: May 30, 2025, 5:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347742
Page 5078 of 34,775
« previous page » next page
Filters