Latest CVE Feed
-
5.4
MEDIUMCVE-2019-16687
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.17
- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4115
IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.21
- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4494
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.28
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4495
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.28
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17074
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.... Read more
Affected Products : xunruicms- EPSS Score: %0.19
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17121
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.... Read more
Affected Products : redcap- EPSS Score: %0.21
- Published: Oct. 04, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17204
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.... Read more
Affected Products : teampass- EPSS Score: %0.19
- Published: Oct. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16416
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.... Read more
Affected Products : hrworks- EPSS Score: %0.21
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10756
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.... Read more
Affected Products : node-red-dashboard- EPSS Score: %0.21
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0369
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnera... Read more
Affected Products : financial_consolidation- EPSS Score: %0.34
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0378
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image result... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.30
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17434
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.... Read more
Affected Products : lavalite- EPSS Score: %0.19
- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16520
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.... Read more
Affected Products : all_in_one_seo_pack- EPSS Score: %1.14
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17576
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.32
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-3019
Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Loan Calculator). Supported versions that are affected are 18.1, 18.2, 18.3 and 19.1. Easily exploitable vulnerability allows low privileg... Read more
Affected Products : banking_digital_experience- EPSS Score: %0.26
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17667
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.... Read more
- EPSS Score: %0.28
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16330
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields p... Read more
Affected Products : express_accounts_accounting- EPSS Score: %0.37
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17207
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page... Read more
Affected Products : broken_link_checker- EPSS Score: %0.29
- Published: Oct. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0377
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cro... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.30
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17189
totemodata 3.0.0_b936 has XSS via a folder name.... Read more
Affected Products : totemodata- EPSS Score: %0.47
- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024