Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-17384 | 1 Eleopard | 1 Animate It\! | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The animate-it plugin before 2.3.4 for WordPress has XSS. | |||||
CVE-2019-17385 | 1 Eleopard | 1 Animate It\! | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The animate-it plugin before 2.3.5 for WordPress has XSS. | |||||
CVE-2019-17378 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). | |||||
CVE-2019-17377 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). | |||||
CVE-2019-17379 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). | |||||
CVE-2019-17376 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). | |||||
CVE-2019-16416 | 1 Hrworks | 1 Hrworks | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report. | |||||
CVE-2019-16417 | 1 Hrworks | 1 Hrworks | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report. | |||||
CVE-2019-6653 | 1 F5 | 1 Big-iq Centralized Management | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles. | |||||
CVE-2019-17368 | 1 S-cms | 1 S-cms | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter. | |||||
CVE-2019-17380 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). | |||||
CVE-2019-16931 | 1 Themeisle | 1 Visualizer | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization. | |||||
CVE-2019-15499 | 2 Apple, Hackmd | 2 Safari, Codimd | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. | |||||
CVE-2019-15750 | 1 Sitos | 1 Sitos Six | 2019-10-08 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||||
CVE-2016-1144 | 1 Websquare | 1 Job-cube | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2019-11656 | 1 Hp | 1 Arcsight Logger | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). | |||||
CVE-2019-17213 | 1 Webarxsecurity | 1 Webarx | 2019-10-08 | 4.3 MEDIUM | 6.1 MEDIUM |
The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header. | |||||
CVE-2019-17121 | 1 Vanderbilt | 1 Redcap | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values. | |||||
CVE-2019-17225 | 1 Intelliants | 1 Subrion | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | |||||
CVE-2019-17226 | 1 Cmsmadesimple | 1 Cms Made Simple | 2019-10-08 | 3.5 LOW | 4.8 MEDIUM |
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field. |