Search Results (44408 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-9696 1 Symantec 1 Vip Enterprise Gateway 2024-11-21 N/A
Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
CVE-2019-9669 1 Wordfence 1 Wordfence 2024-11-21 N/A
The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as the firewall rules are not maintained as part of the Wordfence software but rather it is a set of rules hosted on vendor servers and pushed to the plugin with no versioning associated. Bypassing a WAF rule doesn't make a WordPress site vulnerable (speaking in terms of software vulnerabilities)
CVE-2019-9661 1 Yzmcms 1 Yzmcms 2024-11-21 N/A
Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
CVE-2019-9660 1 Yzmcms 1 Yzmcms 2024-11-21 N/A
Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
CVE-2019-9650 1 Upcoming Events Project 1 Upcoming Events 2024-11-21 N/A
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
CVE-2019-9647 1 Gilacms 1 Gila Cms 2024-11-21 N/A
Gila CMS 1.9.1 has XSS.
CVE-2019-9646 1 Codepeople 1 Contact Form Email 2024-11-21 N/A
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
CVE-2019-9644 1 Jupyter 1 Notebook 2024-11-21 N/A
An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.
CVE-2019-9606 1 Personal Video Collection Script Project 1 Personal Video Collection Script 2024-11-21 N/A
PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature.
CVE-2019-9605 1 Online Lottery Php Readymade Script Project 1 Online Lottery Php Readymade Script 2024-11-21 N/A
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload.
CVE-2019-9595 1 Appcms 1 Appcms 2024-11-21 N/A
AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.
CVE-2019-9593 1 Mitel 1 Connect Onsite 2024-11-21 6.1 Medium
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2019-9592 1 Mitel 1 Connect Onsite 2024-11-21 6.1 Medium
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CVE-2019-9591 1 Mitel 1 Connect Onsite 2024-11-21 6.1 Medium
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
CVE-2019-9580 1 Stackstorm 1 Stackstorm 2024-11-21 N/A
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
CVE-2019-9576 1 Adenion 1 Blog2social 2024-11-21 N/A
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
CVE-2019-9575 1 Quizandsurveymaster 1 Quiz And Survey Master 2024-11-21 N/A
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
CVE-2019-9570 1 Yzmcms 1 Yzmcms 2024-11-21 N/A
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
CVE-2019-9567 1 Incsub 1 Forminator 2024-11-21 6.1 Medium
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
CVE-2019-9558 1 Mailtraq 1 Webmail 2024-11-21 N/A
Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.