Latest CVE Feed
-
5.4
MEDIUMCVE-2019-4495
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.28
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17074
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.... Read more
Affected Products : xunruicms- EPSS Score: %0.19
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17121
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.... Read more
Affected Products : redcap- EPSS Score: %0.21
- Published: Oct. 04, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17204
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.... Read more
Affected Products : teampass- EPSS Score: %0.19
- Published: Oct. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16416
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.... Read more
Affected Products : hrworks- EPSS Score: %0.21
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10756
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.... Read more
Affected Products : node-red-dashboard- EPSS Score: %0.21
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0369
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnera... Read more
Affected Products : financial_consolidation- EPSS Score: %0.34
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0378
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image result... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.30
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17434
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.... Read more
Affected Products : lavalite- EPSS Score: %0.19
- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16520
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.... Read more
Affected Products : all_in_one_seo_pack- EPSS Score: %1.14
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17576
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.32
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-3019
Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Loan Calculator). Supported versions that are affected are 18.1, 18.2, 18.3 and 19.1. Easily exploitable vulnerability allows low privileg... Read more
Affected Products : banking_digital_experience- EPSS Score: %0.26
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17667
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.... Read more
- EPSS Score: %0.28
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16330
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields p... Read more
Affected Products : express_accounts_accounting- EPSS Score: %0.37
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17207
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page... Read more
Affected Products : broken_link_checker- EPSS Score: %0.29
- Published: Oct. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0377
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cro... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.30
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17189
totemodata 3.0.0_b936 has XSS via a folder name.... Read more
Affected Products : totemodata- EPSS Score: %0.47
- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4459
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun... Read more
Affected Products : cloud_orchestrator- EPSS Score: %0.19
- Published: Oct. 24, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4396
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers ... Read more
Affected Products : cloud_orchestrator- EPSS Score: %0.18
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4461
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting ... Read more
Affected Products : cloud_orchestrator- EPSS Score: %0.19
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024