Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-20375 | 1 Psi | 1 Electronic Logbook | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.
|
|||||
| CVE-2019-20374 | 3 Apple, Linux, Typora | 3 Macos, Linux Kernel, Typora | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
|
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code execution in an unsandboxed environment.
|
|||||
| CVE-2019-20366 | 1 Igniterealtime | 1 Openfire | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
|
|||||
| CVE-2019-20365 | 1 Igniterealtime | 1 Openfire | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
|
|||||
| CVE-2019-20364 | 1 Igniterealtime | 1 Openfire | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
|
|||||
| CVE-2019-20363 | 1 Igniterealtime | 1 Openfire | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
|
|||||
| CVE-2019-20336 | 1 Advanced Real Estate Script Project | 1 Advanced Real Estate Script | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
|
|||||
| CVE-2019-20223 | 1 Sitracker | 1 Support Incident Tracker | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235.
|
|||||
| CVE-2019-20222 | 1 Sitracker | 1 Support Incident Tracker | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
|
|||||
| CVE-2019-20221 | 1 Sitracker | 1 Support Incident Tracker | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.
|
|||||
| CVE-2019-20220 | 1 Sitracker | 1 Support Incident Tracker | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
|
|||||
| CVE-2019-20212 | 1 Cththemes | 3 Citybook, Easybook, Townhub | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
|
|||||
| CVE-2019-20211 | 1 Cththemes | 3 Citybook, Easybook, Townhub | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
|
|||||
| CVE-2019-20210 | 1 Cththemes | 3 Citybook, Easybook, Townhub | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
|
|||||
| CVE-2019-20209 | 1 Cththemes | 3 Citybook, Easybook, Townhub | 2024-11-21 | 6.4 MEDIUM | 7.5 HIGH |
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.
|
|||||
| CVE-2019-20204 | 1 Postieplugin | 1 Postie | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.
|
|||||
| CVE-2019-20182 | 1 Fooplugins | 1 Foogallery | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
|
|||||
| CVE-2019-20181 | 1 Getawesomesupport | 1 Awesome Support | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
|
|||||
| CVE-2019-20174 | 1 Auth0 | 1 Lock | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
|
|||||
| CVE-2019-20173 | 1 Auth0 | 1 Login By Auth0 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
|
|||||
| CVE-2019-20154 | 1 Determine | 1 Contract Lifecycle Management | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripting (XSS) vulnerability in multiple getchart.jsp parameters allows remote attackers to inject arbitrary web script or HTML.
|
|||||
| CVE-2019-20152 | 1 Treasuryxpress | 1 Treasuryxpress | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed throughout the application. A malicious payload can be injected within the Custom Workflow component and inserted via the Create New Workflow field. As a result, the payload is executed via the navigation bar throughout the application.
|
|||||
| CVE-2019-20151 | 1 Treasuryxpress | 1 Treasuryxpress | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed by the application's administrator(s). A malicious payload can be injected within the Multi Approval security component and inserted via the Note field. As a result, the payload is executed by the application's administrator(s).
|
|||||
| CVE-2019-20141 | 1 Laborator | 1 Neon | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
|
|||||
| CVE-2019-20139 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
|
|||||
| CVE-2019-20102 | 1 Atlassian | 1 Confluence Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
|
|||||
| CVE-2019-20076 | 1 Netis-systems | 2 Dl4343, Dl4343 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
|
|||||
| CVE-2019-20075 | 1 Netis-systems | 2 Dl4343, Dl4343 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
|
|||||
| CVE-2019-20073 | 1 Netis-systems | 2 Dl4343, Dl4343 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
|
|||||
| CVE-2019-20072 | 1 Netis-systems | 2 Dl4343, Dl4343 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).
|
|||||
| CVE-2019-20070 | 1 Netis-systems | 2 Dl4343, Dl4343 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).
|
|||||
| CVE-2019-20058 | 1 Boltcms | 1 Bolt | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040
|
|||||
| CVE-2019-20042 | 2 Debian, Wordpress | 2 Debian Linux, Wordpress | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
|
|||||
| CVE-2019-20008 | 1 Archerysec | 1 Archery | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
|
|||||
| CVE-2019-20003 | 1 Dicube | 1 Easescreen Crystal | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication.
|
|||||
| CVE-2019-1973 | 1 Cisco | 1 Enterprise Network Function Virtualization Infrastructure | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker could exploit this vulnerability by modifying a log file with malicious code and getting a user to view the modified log file. A successful exploit ...
Show More |
|||||
| CVE-2019-1956 | 1 Cisco | 2 Spa112 2-port Phone Adapter, Spa112 2-port Phone Adapter Firmware | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A vulnerability in the web-based interface of the Cisco SPA112 2-Port Phone Adapter could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the device. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected device. An attacker could exploit this vulnerability by inserting malicious code in one of the configuration fields. A successful exploit could allow the attacker to exe ...
Show More |
|||||
| CVE-2019-1941 | 1 Cisco | 1 Identity Services Engine | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could ...
Show More |
|||||
| CVE-2019-1882 | 1 Cisco | 1 Industrial Network Director | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An attacker could exploit this vulnerability by sending requests containing malicious values to the affected system. A successful exploit could allow the attacker to conduct XSS attacks.
|
|||||
| CVE-2019-1875 | 1 Cisco | 1 Prime Service Catalog | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by adding specific strings to multiple configuration fields. A successful exploit could allow the attacker to execute ar ...
Show More |
|||||