Latest CVE Feed
-
5.4
MEDIUMCVE-2019-14731
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.... Read more
Affected Products : zentao- EPSS Score: %0.19
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10373
A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.... Read more
Affected Products : build_pipeline- EPSS Score: %0.12
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14748
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file conten... Read more
Affected Products : osticket- EPSS Score: %0.52
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14792
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.... Read more
Affected Products : wp_go_maps- EPSS Score: %0.21
- Published: Aug. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0334
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hij... Read more
Affected Products : businessobjects_business_intelligence_platform businessobjects_business_intelligence- EPSS Score: %0.26
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-17790
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.... Read more
Affected Products : master_data_online- EPSS Score: %0.21
- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-15314
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %0.16
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20986
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.... Read more
Affected Products : advanced_custom_fields- EPSS Score: %0.23
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-15778
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.... Read more
Affected Products : additional_variation_images_for_woocommerce- EPSS Score: %0.39
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.21
- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- EPSS Score: %0.42
- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4149
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site... Read more
- EPSS Score: %0.28
- Published: Sep. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16173
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,... Read more
Affected Products : limesurvey- EPSS Score: %0.59
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16178
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.... Read more
Affected Products : limesurvey- EPSS Score: %0.34
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18601
The examapp plugin 1.0 for WordPress has XSS via exam input text fields.... Read more
Affected Products : ibps_online_exam- EPSS Score: %0.15
- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16193
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.... Read more
- EPSS Score: %0.18
- Published: Sep. 11, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-1010147
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.... Read more
- EPSS Score: %0.18
- Published: Jul. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-6835
A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15)... Read more
- EPSS Score: %0.34
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16216
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server using the... Read more
Affected Products : zulip_server- EPSS Score: %0.30
- Published: Sep. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-9393
The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.... Read more
Affected Products : users_ultra_membership- EPSS Score: %0.18
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024