Latest CVE Feed
-
5.4
MEDIUMCVE-2019-14298
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.... Read more
Affected Products : one_reporter- EPSS Score: %0.18
- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-1105
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker ... Read more
Affected Products : outlook- EPSS Score: %0.53
- Published: Jul. 29, 2019
- Modified: May. 20, 2025
-
5.4
MEDIUMCVE-2019-1020005
invenio-communities before 1.0.0a20 allows XSS.... Read more
Affected Products : invenio-communities- EPSS Score: %0.21
- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-11199
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vul... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.49
- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14386
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).... Read more
Affected Products : cpanel- EPSS Score: %0.30
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4285
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijac... Read more
Affected Products : websphere_application_server- EPSS Score: %0.03
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-10360
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.... Read more
- EPSS Score: %0.12
- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14456
Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server) sends crafted text to a serial po... Read more
Affected Products : opengear- EPSS Score: %0.21
- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20878
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20881
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20884
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).... Read more
Affected Products : cpanel- EPSS Score: %0.21
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10853
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).... Read more
Affected Products : cpanel- EPSS Score: %0.26
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-1010124
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administr... Read more
Affected Products : woocommerce_product_feed- EPSS Score: %0.32
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20915
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10827
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).... Read more
Affected Products : cpanel- EPSS Score: %0.26
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18402
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18417
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18419
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18420
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).... Read more
Affected Products : cpanel- EPSS Score: %0.34
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7921
A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to the product catalog ... Read more
Affected Products : magento- EPSS Score: %0.10
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024