Latest CVE Feed
-
5.4
MEDIUMCVE-2019-4454
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.24
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-3517
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.... Read more
- EPSS Score: %0.28
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14343
TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.... Read more
Affected Products : tematres- EPSS Score: %0.38
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4569
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : tivoli_netcool\/impact- EPSS Score: %0.24
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-0203
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bo... Read more
- EPSS Score: %0.24
- Published: Nov. 22, 2019
- Modified: Mar. 31, 2025
-
5.4
MEDIUMCVE-2011-3606
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege,... Read more
Affected Products : jboss_application_server- EPSS Score: %0.40
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-4457
Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.... Read more
Affected Products : cloudera_manager- EPSS Score: %0.19
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14449
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.... Read more
Affected Products : cloudera_manager- EPSS Score: %0.34
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-13935
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions <... Read more
Affected Products : polarion- EPSS Score: %0.40
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-9271
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.... Read more
Affected Products : cloudera_manager- EPSS Score: %0.34
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-5271
There is an information leak vulnerability in Huawei smart speaker Myna. When the smart speaker is paired with the cloud through Wi-Fi, the speaker incorrectly processes some data. Attackers can exploit this vulnerability to read and modify specific confi... Read more
- EPSS Score: %0.08
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4468
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
Affected Products : cloud_pak_system- EPSS Score: %0.24
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18993
OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).... Read more
Affected Products : openwrt- EPSS Score: %0.28
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18992
OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).... Read more
Affected Products : openwrt- EPSS Score: %0.28
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19596
GitBook through 2.6.9 allows XSS via a local .md file.... Read more
Affected Products : gitbook- EPSS Score: %0.27
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.26
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4428
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre... Read more
Affected Products : watson_assistant_for_ibm_cloud_pak_for_data- EPSS Score: %0.19
- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19198
The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.... Read more
Affected Products : kalender- EPSS Score: %0.79
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-13182
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.... Read more
- EPSS Score: %1.98
- Published: Dec. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16563
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties.... Read more
Affected Products : mission_control- EPSS Score: %0.23
- Published: Dec. 17, 2019
- Modified: Nov. 21, 2024