Export limit exceeded: 18199 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 44266 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (44266 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-15482 | 1 Selectize-plugin-a11y Project | 1 Selectize-plugin-a11y | 2024-11-21 | N/A |
| selectize-plugin-a11y before 1.1.0 has XSS via the msg field. | ||||
| CVE-2019-15481 | 1 Kimai | 1 Kimai 2 | 2024-11-21 | N/A |
| Kimai v2 before 1.1 has XSS via a timesheet description. | ||||
| CVE-2019-15480 | 1 Domoticz | 1 Domoticz | 2024-11-21 | N/A |
| Domoticz 4.10717 has XSS via item.Name. | ||||
| CVE-2019-15479 | 1 Status Board Project | 1 Status Board | 2024-11-21 | N/A |
| Status Board 1.1.81 has reflected XSS via dashboard.ts. | ||||
| CVE-2019-15478 | 1 Status Board Project | 1 Status Board | 2024-11-21 | N/A |
| Status Board 1.1.81 has reflected XSS via logic.ts. | ||||
| CVE-2019-15477 | 1 Jooby | 1 Jooby | 2024-11-21 | N/A |
| Jooby before 1.6.4 has XSS via the default error handler. | ||||
| CVE-2019-15476 | 1 Former Project | 1 Former | 2024-11-21 | N/A |
| Former before 4.2.1 has XSS via a checkbox value. | ||||
| CVE-2019-15331 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2024-11-21 | N/A |
| The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. | ||||
| CVE-2019-15328 | 1 Codection | 1 Import Users From Csv With Meta | 2024-11-21 | N/A |
| The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. | ||||
| CVE-2019-15327 | 1 Codection | 1 Import Users From Csv With Meta | 2024-11-21 | N/A |
| The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. | ||||
| CVE-2019-15317 | 1 Givewp | 1 Givewp | 2024-11-21 | N/A |
| The give plugin before 2.4.7 for WordPress has XSS via a donor name. | ||||
| CVE-2019-15314 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2024-11-21 | N/A |
| tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. | ||||
| CVE-2019-15313 | 1 Zimbra | 1 Collaboration Server | 2024-11-21 | 6.1 Medium |
| In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability. | ||||
| CVE-2019-15278 | 1 Cisco | 2 Finesse, Unified Contact Center Express | 2024-11-21 | 6.1 Medium |
| A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information. | ||||
| CVE-2019-15233 | 1 Oldstreetsolutions | 1 Live Input Macros | 2024-11-21 | 6.1 Medium |
| The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie. | ||||
| CVE-2019-15230 | 1 Librenms | 1 Librenms | 2024-11-21 | N/A |
| LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account. | ||||
| CVE-2019-15228 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | N/A |
| FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors. | ||||
| CVE-2019-15227 | 1 Getflightpath | 1 Flightpath | 2024-11-21 | N/A |
| FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions. | ||||
| CVE-2019-15127 | 1 Vanderbilt | 1 Redcap | 2024-11-21 | N/A |
| REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file. | ||||
| CVE-2019-15124 | 1 Mediawiki | 1 Mobilefrontend | 2024-11-21 | 6.1 Medium |
| In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33. | ||||