Latest CVE Feed
-
5.4
MEDIUMCVE-2019-19266
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.... Read more
Affected Products : mail_server- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14918
XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via crafted DHCP request packets to etc_ro/web/internet/dhcpclii... Read more
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6303
SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.... Read more
Affected Products : disclosure_management- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2646
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Command Line Interface). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows low privilege... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-17651
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS)... Read more
Affected Products : fortisiem- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-0161
Havalite CMS 1.1.7 has a stored XSS vulnerability... Read more
Affected Products : havalite- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8498
XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privi... Read more
Affected Products : gistpress- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4451
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru... Read more
Affected Products : security_identity_manager- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-15253
A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interfa... Read more
- Published: Feb. 05, 2020
- Modified: Jul. 23, 2025
-
5.4
MEDIUMCVE-2020-8812
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.... Read more
Affected Products : bludit- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2112
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.... Read more
Affected Products : git_parameter- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2122
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.... Read more
Affected Products : brakeman- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18791
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.... Read more
Affected Products : cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware xm1145_firmware xm3150_firmware mx71x_firmware mx81x_firmware xm51xx_firmware +150 more products- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18210
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: th... Read more
Affected Products : moodle- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4429
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8824
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.... Read more
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9339
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.... Read more
Affected Products : soplanning- Published: Feb. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19990
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /monitor/s_headmodel.p... Read more
Affected Products : visual_access_manager- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19991
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /vam/vam_anagraphic... Read more
Affected Products : visual_access_manager- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8951
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.... Read more
Affected Products : accurate_reconciliation- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024