Latest CVE Feed
-
9.6
CRITICALCVE-2025-3621
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use o... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.6
CRITICALCVE-2019-3709
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the conte... Read more
Affected Products : emc_isilonsd_management_server- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-15074
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is ... Read more
Affected Products : mantisbt- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-13364
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.... Read more
Affected Products : piwigo- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-13923
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a mal... Read more
Affected Products : ie\/wsn-pa_link_wirelesshart_gateway_firmware ie\/wsn-pa_link_wirelesshart_gateway- Published: Sep. 13, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-17330
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scri... Read more
Affected Products : ebx- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-15897
beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).... Read more
Affected Products : beegfs- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-20374
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability ... Read more
- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2014-5039
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : eucalyptus_management_console- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-0872
A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspe... Read more
Affected Products : application_inspector- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-19676
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a... Read more
Affected Products : arxes-tolina- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-14428
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 be... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk842_firmware rbr840_firmware rbs840_firmware rbk753_firmware +14 more products- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-9413
The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contain a vulnerability that theoretically allows an attacker ... Read more
- Published: Jun. 30, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-5901
In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.... Read more
Affected Products : nginx_controller- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-15124
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially le... Read more
Affected Products : goobi_viewer_core- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-9691
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : magento- Published: Jul. 29, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-6320
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and ... Read more
Affected Products : marketing- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-15182
The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit f... Read more
- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26157
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.... Read more
- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26903
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 b... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbk752 rbr750 rbs750 +4 more products- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024