Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-12315 | 1 Samsung | 2 Scx-824, Scx-824 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter.
|
|||||
| CVE-2019-12313 | 1 Dollarshaveclub | 1 Shave | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
|
|||||
| CVE-2019-12311 | 1 Sandline | 1 Centraleyezer | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.
|
|||||
| CVE-2019-12308 | 1 Djangoproject | 1 Django | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.
|
|||||
| CVE-2019-12299 | 1 Sandline | 1 Centraleyezer | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section.
|
|||||
| CVE-2019-12250 | 1 Identityserver | 1 Identityserver4 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
IdentityServer IdentityServer4 through 2.4 has stored XSS via the httpContext to the host/Extensions/RequestLoggerMiddleware.cs LogForErrorContext method, which can be triggered by viewing a log. NOTE: the software maintainer disputes that this is a vulnerability because the request logger is not part of IdentityServer but only our development test host
|
|||||
| CVE-2019-12205 | 1 Silverstripe | 1 Silverstripe | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
|
|||||
| CVE-2019-12195 | 1 Tp-link | 2 Tl-wr840n, Tl-wr840n Firmware | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.
|
|||||
| CVE-2019-12190 | 1 Control-webpanel | 1 Webpanel | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.
|
|||||
| CVE-2019-12189 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
|
|||||
| CVE-2019-12186 | 1 Sylius | 2 Grid, Sylius | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid 1.0.x through 1.0.18, 1.1.x through 1.1.18, 1.2.x through 1.2.17, 1.3.x through 1.3.12, 1.4.x through 1.4.4, and 1.5.0 allows an attacker (an admin in the sylius/sylius case) to perform XSS by injecting malicious code into a field displayed in a grid with the "string" field type. The ...
Show More |
|||||
| CVE-2019-12184 | 1 Boostio | 1 Boostnote | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.
|
|||||
| CVE-2019-12167 | 1 Emerson | 2 Liebert Challenger, Liebert Challenger Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
httpGetSet/httpGet.htm on Emerson Network Power Liebert Challenger 5.1E0.5 devices allows XSS via the statusstr parameter.
|
|||||
| CVE-2019-12139 | 1 Ez | 2 Ezplatform-admin-ui, Ezplatform-page-builder | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x before 1.4.4, and ezplatform-page-builder 1.1.x before 1.1.5 and 1.2.x before 1.2.4.
|
|||||
| CVE-2019-12136 | 1 Boostio | 1 Boostnote | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
There is XSS in BoostIO Boostnote 0.11.15 via a label named mermaid, as demonstrated by a crafted SRC attribute of an IFRAME element.
|
|||||
| CVE-2019-12095 | 1 Horde | 1 Groupware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.
|
|||||
| CVE-2019-12094 | 1 Horde | 1 Groupware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.
|
|||||
| CVE-2019-12047 | 1 Gridea | 1 Gridea | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
|
|||||
| CVE-2019-12043 | 1 Remarkable Project | 1 Remarkable | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
|
|||||
| CVE-2019-11999 | 1 Hpe | 1 Opencall Media Platform | 2024-11-21 | 4.9 MEDIUM | 6.9 MEDIUM |
|
Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross site scripting. HPE has made the following updates available to resolve the vulnerability in the impacted versions of OCMP. * For OCMP version 4.4.X - please upgrade to OCMP 4.4.8 and then install RP806 * For OCMP 4.5.x please contact HPE Technical Support to obtain the necessary software updates.
|
|||||
| CVE-2019-11997 | 1 Hp | 1 Enhanced Internet Usage Manager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the vulnerability in eIUM. The eIUM 8.3 FP01 customers are advised to install eIUM83FP01Patch_QXCR1001711284.20190806-1244 patch. The eIUM 9.0 customers are advised to upgrade to eIUM 9.0 FP02 PI5 or later versions. For other ...
Show More |
|||||
| CVE-2019-11992 | 1 Hp | 1 Oneview For Vmware Vcenter | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting.
|
|||||
| CVE-2019-11982 | 1 Hp | 39 Integrated Lights-out 4 Firmware, Integrated Lights-out 5 Firmware, Proliant Bl460c Gen10 and 36 more | 2024-11-21 | 7.6 HIGH | 8.3 HIGH |
|
A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
|
|||||
| CVE-2019-11928 | 1 Whatsapp | 1 Whatsapp Desktop | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.
|
|||||
| CVE-2019-11877 | 1 Pix-link | 2 Lv-wr09, Lv-wr09 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
XSS on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID.
|
|||||
| CVE-2019-11876 | 2 Drupal, Prestashop | 2 Drupal, Prestashop | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
|
|||||
| CVE-2019-11871 | 1 Custom Field Suite Project | 1 Custom Field Suite | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
|
|||||
| CVE-2019-11870 | 1 S9y | 1 Serendipity | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
|
|||||
| CVE-2019-11869 | 1 Yuzopro | 1 Yuzo | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.
|
|||||
| CVE-2019-11846 | 1 Dotcms | 1 Dotcms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
|
|||||
| CVE-2019-11845 | 1 Ricoh | 2 Sp 4510dn, Sp 4510dn Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
|
|||||
| CVE-2019-11844 | 1 Ricoh | 2 Sp 4520dn, Sp 4520dn Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter.
|
|||||
| CVE-2019-11828 | 1 Synology | 1 Office | 2024-11-21 | 3.5 LOW | 5.5 MEDIUM |
|
Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
|||||
| CVE-2019-11827 | 1 Synology | 1 Note Station | 2024-11-21 | 3.5 LOW | 6.5 MEDIUM |
|
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbitrary web script or HTML via the object_id parameter.
|
|||||
| CVE-2019-11825 | 1 Synology | 1 Calendar | 2024-11-21 | 3.5 LOW | 6.5 MEDIUM |
|
Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
|
|||||
| CVE-2019-11818 | 1 Alkacon | 1 Opencms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.
|
|||||
| CVE-2019-11814 | 1 Misp | 1 Misp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.
|
|||||
| CVE-2019-11813 | 1 Misp | 1 Misp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.
|
|||||
| CVE-2019-11812 | 1 Misp | 1 Misp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.
|
|||||
| CVE-2019-11809 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data, which leads to a potential XSS attack vector.
|
|||||