Total
36974 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-14996 | 1 Atlassian | 1 Jira Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter. | |||||
CVE-2019-14987 | 1 Schben | 1 Framework | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions. | |||||
CVE-2019-14976 | 1 Icmsdev | 1 Icms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. | |||||
CVE-2019-14974 | 1 Sugarcrm | 1 Sugarcrm | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. | |||||
CVE-2019-14967 | 1 Frappe | 1 Frappe | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability. | |||||
CVE-2019-14961 | 1 Jetbrains | 1 Upsource | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. | |||||
CVE-2019-14953 | 2 Jetbrains, Mozilla | 2 Youtrack, Firefox | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. | |||||
CVE-2019-14952 | 1 Jetbrains | 1 Youtrack | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. | |||||
CVE-2019-14950 | 1 3cx | 1 Live Chat | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. | |||||
CVE-2019-14949 | 1 Wpseeds | 1 Wp Database Backup | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The wp-database-backup plugin before 5.1.2 for WordPress has XSS. | |||||
CVE-2019-14948 | 1 Najeebmedia | 1 Ppom For Woocommerce | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure. | |||||
CVE-2019-14947 | 1 Ultimatemember | 1 Ultimate Member | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. | |||||
CVE-2019-14946 | 1 Ultimatemember | 1 Ultimate Member | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. | |||||
CVE-2019-14945 | 1 Ultimatemember | 1 Ultimate Member | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The ultimate-member plugin before 2.0.54 for WordPress has XSS. | |||||
CVE-2019-14928 | 2 Inea, Mitsubishielectric | 4 Me-rtu, Me-rtu Firmware, Smartrtu and 1 more | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page. | |||||
CVE-2019-14918 | 1 Billion | 2 Sg600 R2, Sg600 R2 Firmware | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via crafted DHCP request packets to etc_ro/web/internet/dhcpcliinfo.asp. | |||||
CVE-2019-14915 | 1 Prise | 1 Adas | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submitting a rogue certificate. | |||||
CVE-2019-14913 | 1 Prise | 1 Adas | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel. | |||||
CVE-2019-14911 | 1 Prise | 1 Adas | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to reflected XSS. | |||||
CVE-2019-14884 | 1 Moodle | 1 Moodle | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages. |