Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-7173 | 1 Croogo | 1 Croogo | 2019-01-29 | 3.5 LOW | 4.8 MEDIUM |
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4. | |||||
CVE-2018-16084 | 2 Google, Redhat | 4 Chrome, Enterprise Linux Desktop, Enterprise Linux Server and 1 more | 2019-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The default selected dialog button in CustomHandlers in Google Chrome prior to 69.0.3497.81 allowed a remote attacker who convinced the user to perform certain operations to open external programs via a crafted HTML page. | |||||
CVE-2019-6979 | 1 Ip History Logs Project | 1 Ip History Logs | 2019-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field. | |||||
CVE-2019-6990 | 1 Zoneminder | 1 Zoneminder | 2019-01-29 | 3.5 LOW | 5.4 MEDIUM |
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI. | |||||
CVE-2018-19727 | 1 Adobe | 1 Experience Manager | 2019-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |||||
CVE-2018-19724 | 1 Adobe | 1 Experience Manager | 2019-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |||||
CVE-2018-19726 | 1 Adobe | 1 Experience Manager | 2019-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |||||
CVE-2019-6803 | 1 Typora | 1 Typora | 2019-01-25 | 4.3 MEDIUM | 6.1 MEDIUM |
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar. | |||||
CVE-2015-9276 | 1 Smartertools | 1 Smartermail | 2019-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password. | |||||
CVE-2015-9281 | 6 Hpe, Ibm, Linux and 3 more | 6 Hp-ux Ipfilter, Aix, Linux Kernel and 3 more | 2019-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. | |||||
CVE-2019-6777 | 1 Zoneminder | 1 Zoneminder | 2019-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter. | |||||
CVE-2018-14846 | 1 Mondula | 1 Multi Step Form | 2019-01-24 | 3.5 LOW | 5.4 MEDIUM |
The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php. | |||||
CVE-2017-18358 | 1 Limesurvey | 1 Limesurvey | 2019-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel. | |||||
CVE-2018-16199 | 1 Toshiba | 4 Hem-gw16a, Hem-gw16a Firmware, Hem-gw26a and 1 more | 2019-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-0698 | 1 Weseek | 1 Growi | 2019-01-23 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-16206 | 1 Ohtanz | 1 Spam-byebye | 2019-01-23 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-20682 | 1 Fork-cms | 1 Fork Cms | 2019-01-23 | 3.5 LOW | 5.4 MEDIUM |
Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section). | |||||
CVE-2016-10737 | 1 S9y | 1 Serendipity | 2019-01-23 | 3.5 LOW | 5.4 MEDIUM |
Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter. | |||||
CVE-2018-20731 | 1 Nedi | 1 Nedi | 2019-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via User-Chat.php. | |||||
CVE-2018-20729 | 1 Nedi | 1 Nedi | 2019-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via the reg parameter in mh.php. |