Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-1273 | 1 Microsoft | 3 Windows 10, Windows Server 2016, Windows Server 2019 | 2019-09-12 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'. | |||||
CVE-2019-16145 | 1 Padrinorb | 1 Padrino-contrib | 2019-09-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption. | |||||
CVE-2019-0361 | 1 Sap | 1 Supplier Relationship Management | 2019-09-11 | 4.3 MEDIUM | 6.1 MEDIUM |
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |||||
CVE-2019-11548 | 1 Gitlab | 1 Gitlab | 2019-09-10 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint. | |||||
CVE-2017-18610 | 1 Magicfields | 1 Magic Fields | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter. | |||||
CVE-2017-18611 | 1 Magicfields | 1 Magic Fields | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter. | |||||
CVE-2017-18601 | 1 Ibps Online Exam Project | 1 Ibps Online Exam | 2019-09-10 | 3.5 LOW | 5.4 MEDIUM |
The examapp plugin 1.0 for WordPress has XSS via exam input text fields. | |||||
CVE-2017-18606 | 1 Theme-fusion | 1 Avada | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The avada theme before 5.1.5 for WordPress has stored XSS. | |||||
CVE-2017-18600 | 1 Ncrafts | 1 Formcraft | 2019-09-10 | 3.5 LOW | 5.4 MEDIUM |
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. | |||||
CVE-2019-6784 | 1 Gitlab | 1 Gitlab | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS. | |||||
CVE-2019-16147 | 1 Liferay | 1 Liferay Portal | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib. | |||||
CVE-2017-18598 | 1 Designmodo | 1 Qards | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php. | |||||
CVE-2017-18599 | 1 Pinfinity Project | 1 Pinfinity | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter. | |||||
CVE-2017-18609 | 1 Magicfields | 1 Magic Fields | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter. | |||||
CVE-2017-18608 | 1 Spot | 1 Spot.im Comments | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues. | |||||
CVE-2019-16182 | 1 Limesurvey | 1 Limesurvey | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files. | |||||
CVE-2019-16178 | 1 Limesurvey | 1 Limesurvey | 2019-09-10 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page. | |||||
CVE-2019-10670 | 1 Librenms | 1 Librenms | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data being injected into these contexts, leading to attacker controlled JavaScript executing in the browser. One example of this is the string parameter in html/pages/inventory.inc.php. | |||||
CVE-2019-16148 | 1 Sakailms | 1 Sakai | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Sakai through 12.6 allows XSS via a chat user name. | |||||
CVE-2017-1000426 | 1 Omniscale | 1 Mapproxy | 2019-09-10 | 4.3 MEDIUM | 6.1 MEDIUM |
MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure. |