Latest CVE Feed
-
5.4
MEDIUMCVE-2019-14298
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.... Read more
Affected Products : one_reporter- EPSS Score: %0.18
- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-1105
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker ... Read more
Affected Products : outlook- EPSS Score: %0.53
- Published: Jul. 29, 2019
- Modified: May. 20, 2025
-
5.4
MEDIUMCVE-2019-1020005
invenio-communities before 1.0.0a20 allows XSS.... Read more
Affected Products : invenio-communities- EPSS Score: %0.21
- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-11199
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vul... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.49
- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14386
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).... Read more
Affected Products : cpanel- EPSS Score: %0.30
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14390
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).... Read more
Affected Products : cpanel- EPSS Score: %0.30
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4285
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijac... Read more
Affected Products : websphere_application_server- EPSS Score: %0.03
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10360
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.... Read more
- EPSS Score: %0.12
- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14456
Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server) sends crafted text to a serial po... Read more
Affected Products : opengear- EPSS Score: %0.21
- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20874
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20876
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20878
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20881
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20884
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10853
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).... Read more
Affected Products : cpanel- EPSS Score: %0.26
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-1010124
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administr... Read more
Affected Products : woocommerce_product_feed- EPSS Score: %0.32
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20915
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10827
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).... Read more
Affected Products : cpanel- EPSS Score: %0.26
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18402
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18417
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024