Latest CVE Feed
-
5.4
MEDIUMCVE-2019-15230
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be ex... Read more
Affected Products : librenms- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4184
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : jazz_reporting_service- Published: May. 29, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4204
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
- Published: May. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25516
WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.... Read more
Affected Products : enterprise_integrator- Published: Oct. 29, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-5398
A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.... Read more
- Published: Aug. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20118
A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripting (D... Read more
Affected Products : server- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-16878
Portainer before 1.22.1 has XSS (issue 2 of 2).... Read more
Affected Products : portainer- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25877
A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.... Read more
Affected Products : blackcat_cms- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19210
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.... Read more
- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19757
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web brows... Read more
Affected Products : xclarity_administrator- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8128
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.... Read more
Affected Products : magento- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8142
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via title of an order when configuring sales payment methods for a ... Read more
Affected Products : magento- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-0103
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user may cause an incorrect Initialization of resource by network issue. A successful exploit of this vulnerability may lead to information disclosure.... Read more
Affected Products : triton_inference_server- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-9606
PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature.... Read more
Affected Products : personal_video_collection_script- Published: Mar. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35704
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.... Read more
Affected Products : daybyday- Published: Dec. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35706
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.... Read more
Affected Products : daybyday- Published: Dec. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4077
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : sterling_b2b_integrator- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-10103
An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute within the browser of any user who opens a specially craf... Read more
Affected Products : zammad- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-10128
SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an attacker to inject malicious JavaSc... Read more
Affected Products : searchblox- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4061
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.... Read more
Affected Products : october- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024