Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-19466 | 1 Sceditor | 1 Sceditor | 2019-12-09 | 4.3 MEDIUM | 6.1 MEDIUM |
SCEditor 2.1.3 allows XSS. | |||||
CVE-2013-0283 | 1 Theforeman | 1 Katello | 2019-12-09 | 3.5 LOW | 5.4 MEDIUM |
Katello: Username in Notification page has cross site scripting | |||||
CVE-2019-19129 | 1 Afterlogic | 2 Aurora, Webmail Pro | 2019-12-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name. | |||||
CVE-2019-4098 | 1 Ibm | 1 Cloud Pak System | 2019-12-09 | 3.5 LOW | 5.4 MEDIUM |
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158020. | |||||
CVE-2019-4467 | 1 Ibm | 1 Cloud Pak System | 2019-12-09 | 3.5 LOW | 5.4 MEDIUM |
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163776. | |||||
CVE-2019-4468 | 1 Ibm | 1 Cloud Pak System | 2019-12-09 | 3.5 LOW | 5.4 MEDIUM |
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163777. | |||||
CVE-2018-15583 | 1 Gnuboard | 1 Gnuboard5 | 2019-12-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter. | |||||
CVE-2019-19133 | 1 Csshero | 1 Csshero | 2019-12-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks. | |||||
CVE-2019-16772 | 1 Serialize-to-js Project | 1 Serialize-to-js | 2019-12-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability. | |||||
CVE-2017-15881 | 1 Keystonejs | 1 Keystone | 2019-12-09 | 3.5 LOW | 4.8 MEDIUM |
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878. | |||||
CVE-2019-7197 | 1 Qnap | 1 Qts | 2019-12-06 | 3.5 LOW | 4.8 MEDIUM |
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version. | |||||
CVE-2019-19596 | 1 Gitbook | 1 Gitbook | 2019-12-06 | 3.5 LOW | 5.4 MEDIUM |
GitBook through 2.6.9 allows XSS via a local .md file. | |||||
CVE-2019-19587 | 1 Wso2 | 1 Enterprise Integrator | 2019-12-06 | 4.3 MEDIUM | 6.1 MEDIUM |
In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console. | |||||
CVE-2014-3875 | 1 Ulli Horlacher | 1 Fex | 2019-12-06 | 4.3 MEDIUM | 6.1 MEDIUM |
The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks | |||||
CVE-2019-15994 | 1 Cisco | 1 Stealthwatch Enterprise | 2019-12-06 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
CVE-2019-15968 | 1 Cisco | 2 Hosted Collaboration Solution, Unified Communications Domain Manager | 2019-12-06 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
CVE-2019-16195 | 1 Centreon | 1 Centreon | 2019-12-05 | 4.3 MEDIUM | 6.1 MEDIUM |
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields. | |||||
CVE-2019-13935 | 1 Siemens | 1 Polarion | 2019-12-05 | 3.5 LOW | 5.4 MEDIUM |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2. | |||||
CVE-2019-13936 | 1 Siemens | 1 Polarion | 2019-12-05 | 3.5 LOW | 5.4 MEDIUM |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2. | |||||
CVE-2019-13934 | 1 Siemens | 1 Polarion | 2019-12-05 | 3.5 LOW | 5.4 MEDIUM |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2. |