Total
36875 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-15095 | 1 Diaowen | 1 Dwsurvey | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. | |||||
CVE-2019-15086 | 1 Prise | 1 Adas | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message. | |||||
CVE-2019-15083 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page. | |||||
CVE-2019-15082 | 1 Yofla | 1 360 Product Rotation | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS. | |||||
CVE-2019-15081 | 1 Opencart | 1 Opencart | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages. | |||||
CVE-2019-15074 | 1 Mantisbt | 1 Mantisbt | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed. | |||||
CVE-2019-15072 | 1 Openfind | 1 Mail2000 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities. | |||||
CVE-2019-15071 | 1 Openfind | 1 Mail2000 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities. | |||||
CVE-2019-15054 | 1 Getmailbird | 1 Mailbird | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbitrary JavaScript in a privileged context via a crafted HTML mail message. This vulnerability is distinct from CVE-2015-4657. | |||||
CVE-2019-15053 | 1 Atlassian | 1 Html Include And Replace Macro | 2024-11-21 | 6.0 MEDIUM | 6.8 MEDIUM |
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element. | |||||
CVE-2019-15037 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1. | |||||
CVE-2019-15008 | 1 Atlassian | 2 Crucible, Fisheye | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter. | |||||
CVE-2019-15007 | 1 Atlassian | 2 Crucible, Fisheye | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch. | |||||
CVE-2019-14996 | 1 Atlassian | 1 Jira Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter. | |||||
CVE-2019-14987 | 1 Schben | 1 Framework | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions. | |||||
CVE-2019-14976 | 1 Icmsdev | 1 Icms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. | |||||
CVE-2019-14974 | 1 Sugarcrm | 1 Sugarcrm | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. | |||||
CVE-2019-14967 | 1 Frappe | 1 Frappe | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability. | |||||
CVE-2019-14961 | 1 Jetbrains | 1 Upsource | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. | |||||
CVE-2019-14953 | 2 Jetbrains, Mozilla | 2 Youtrack, Firefox | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. |