Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-14804 | 1 Una | 1 Una | 2019-08-14 | 3.5 LOW | 4.8 MEDIUM |
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing. | |||||
CVE-2019-12950 | 1 Teampass | 1 Teampass | 2019-08-14 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. | |||||
CVE-2019-14797 | 1 10web | 1 Photo Gallery | 2019-08-14 | 3.5 LOW | 5.4 MEDIUM |
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. | |||||
CVE-2019-14546 | 1 Espocrm | 1 Espocrm | 2019-08-14 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his email signature, which fires when the victim replies or forwards the mail, thus helping him steal victims' cookies (hence compromising their accounts). | |||||
CVE-2019-9834 | 1 Netdata | 1 Netdata | 2019-08-14 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot. | |||||
CVE-2018-20827 | 1 Atlassian | 1 Jira | 2019-08-13 | 3.5 LOW | 5.4 MEDIUM |
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter. | |||||
CVE-2019-10933 | 1 Siemens | 4 Spectrum Power 3, Spectrum Power 4, Spectrum Power 5 and 1 more | 2019-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All versions < v5.50), Spectrum Power 7 (Corporate User Interface) (All versions <= v2.20). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user does not need to be logged into the web interface in order for the exploitation to succeed.At the stage of publishing this security advisory no public exploitation is known. | |||||
CVE-2019-14696 | 1 Open-school | 1 Open-school | 2019-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. | |||||
CVE-2017-18402 | 1 Cpanel | 1 Cpanel | 2019-08-13 | 3.5 LOW | 5.4 MEDIUM |
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336). | |||||
CVE-2019-11198 | 1 Sitecore | 1 Cms | 2019-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) #300583 - List Manager Dashboard module, (2) #307638 - Campaign Creator module, (3) #316994 - Attributes field, (4) I#316995 - Icon Selection module, (5) #317000 - Latitude field, (6) #317000 - Longitude field, (7) #317017 - UploadPackage2.aspx module, (8) #317072 - Context menu, or (9) I#317073 - Insert from Template dialog. | |||||
CVE-2019-14772 | 1 Verdaccio | 1 Verdaccio | 2019-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
verdaccio before 3.12.0 allows XSS. | |||||
CVE-2014-4035 | 1 Bestsoftinc | 1 Advance Hotel Booking System | 2019-08-12 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |||||
CVE-2016-10795 | 1 Cpanel | 1 Cpanel | 2019-08-12 | 4.3 MEDIUM | 6.1 MEDIUM |
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). | |||||
CVE-2017-18408 | 1 Cpanel | 1 Cpanel | 2019-08-12 | 3.5 LOW | 5.4 MEDIUM |
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282). | |||||
CVE-2019-14747 | 1 Diaowen | 1 Dwsurvey | 2019-08-12 | 4.3 MEDIUM | 6.1 MEDIUM |
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter. | |||||
CVE-2019-13380 | 1 Keynto | 1 Team Password Manager | 2019-08-09 | 4.3 MEDIUM | 6.1 MEDIUM |
KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault. | |||||
CVE-2019-14548 | 1 Espocrm | 1 Espocrm | 2019-08-09 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious JavaScript inside the body of the article, thus helping him steal victims' cookies (hence compromising their accounts). | |||||
CVE-2019-14549 | 1 Espocrm | 1 Espocrm | 2019-08-09 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the publicly accessible link. | |||||
CVE-2019-14547 | 1 Espocrm | 1 Espocrm | 2019-08-09 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker could inject the JavaScript inside the filename and send it to users, thus helping him steal victims' cookies (hence compromising their accounts). | |||||
CVE-2019-14550 | 1 Espocrm | 1 Espocrm | 2019-08-09 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit Dashboard button, thus helping him steal victims' cookies (hence compromising their accounts). |