Search Results (43190 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-20522 1 Ilch 1 Ilch Cms 2024-11-21 6.1 Medium
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
CVE-2019-20521 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
CVE-2019-20520 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
CVE-2019-20519 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVE-2019-20518 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CVE-2019-20517 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
CVE-2019-20516 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
CVE-2019-20515 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
CVE-2019-20514 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
CVE-2019-20513 1 Edx 1 Open Edx 2024-11-21 6.1 Medium
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
CVE-2019-20512 1 Open.edx 1 Ironwood 2024-11-21 6.1 Medium
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
CVE-2019-20511 1 Frappe 1 Erpnext 2024-11-21 6.1 Medium
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
CVE-2019-20497 1 Cpanel 1 Cpanel 2024-11-21 5.4 Medium
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2019-20493 1 Cpanel 1 Cpanel 2024-11-21 6.1 Medium
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2019-20486 1 Netgear 2 Wnr1000, Wnr1000 Firmware 2024-11-21 6.1 Medium
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.
CVE-2019-20483 1 Vikisolutions 1 Vera 2024-11-21 5.4 Medium
An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.
CVE-2019-20471 1 Tk-star 2 Q90 Junior Gps Horloge, Q90 Junior Gps Horloge Firmware 2024-11-21 7.8 High
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that this password can be used in combination with CVE-2019-20470.
CVE-2019-20443 1 Wso2 3 Api Manager, Enterprise Integrator, Identity Server 2024-11-21 4.8 Medium
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.
CVE-2019-20442 1 Wso2 3 Api Manager, Enterprise Integrator, Identity Server 2024-11-21 4.8 Medium
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
CVE-2019-20441 1 Wso2 1 Api Manager 2024-11-21 4.8 Medium
An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.