Latest CVE Feed
-
5.4
MEDIUMCVE-2019-16890
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.... Read more
Affected Products : halo- Published: Sep. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-9423
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.... Read more
Affected Products : plugnedit- Published: Sep. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16685
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.... Read more
Affected Products : dolibarr_erp\/crm- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4115
IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : websphere_extreme_scale- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4494
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po... Read more
Affected Products : jazz_reporting_service- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4495
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po... Read more
Affected Products : jazz_reporting_service- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17074
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.... Read more
Affected Products : xunruicms- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17121
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.... Read more
Affected Products : redcap- Published: Oct. 04, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16416
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.... Read more
Affected Products : hrworks- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17434
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.... Read more
Affected Products : lavalite- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17576
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.... Read more
Affected Products : dolibarr_erp\/crm- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-3019
Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Loan Calculator). Supported versions that are affected are 18.1, 18.2, 18.3 and 19.1. Easily exploitable vulnerability allows low privileg... Read more
Affected Products : banking_digital_experience- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17207
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page... Read more
Affected Products : broken_link_checker- Published: Oct. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17189
totemodata 3.0.0_b936 has XSS via a folder name.... Read more
Affected Products : totemodata- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4459
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun... Read more
Affected Products : cloud_orchestrator- Published: Oct. 24, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4396
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers ... Read more
Affected Products : cloud_orchestrator- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4461
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting ... Read more
Affected Products : cloud_orchestrator- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-9758
An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators from security/permissions.view, security/addUsers.view, or wiki/Administration/page.view in the admin panel, leading... Read more
Affected Products : labkey_server- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2010-3660
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.... Read more
Affected Products : typo3- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18664
The Log module in SECUDOS DOMOS before 5.6 allows XSS.... Read more
Affected Products : domos- Published: Nov. 02, 2019
- Modified: Nov. 21, 2024