Search Results (43125 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15037 1 Jetbrains 1 Teamcity 2024-11-21 6.1 Medium
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
CVE-2019-15017 1 Zingbox 1 Inspector 2024-11-21 8.4 High
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.
CVE-2019-15015 1 Zingbox 1 Inspector 2024-11-21 8.4 High
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system.
CVE-2019-15008 1 Atlassian 2 Crucible, Fisheye 2024-11-21 6.1 Medium
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
CVE-2019-15007 1 Atlassian 2 Crucible, Fisheye 2024-11-21 4.8 Medium
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.
CVE-2019-14996 1 Atlassian 1 Jira Server 2024-11-21 6.1 Medium
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
CVE-2019-14987 1 Schben 1 Framework 2024-11-21 N/A
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
CVE-2019-14976 1 Icmsdev 1 Icms 2024-11-21 N/A
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
CVE-2019-14974 1 Sugarcrm 1 Sugarcrm 2024-11-21 N/A
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
CVE-2019-14967 1 Frappe 1 Frappe 2024-11-21 N/A
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
CVE-2019-14961 1 Jetbrains 1 Upsource 2024-11-21 6.1 Medium
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
CVE-2019-14953 2 Jetbrains, Mozilla 2 Youtrack, Firefox 2024-11-21 6.1 Medium
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
CVE-2019-14952 1 Jetbrains 1 Youtrack 2024-11-21 6.1 Medium
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
CVE-2019-14950 1 3cx 1 Live Chat 2024-11-21 N/A
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
CVE-2019-14949 1 Wpseeds 1 Wp Database Backup 2024-11-21 6.1 Medium
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
CVE-2019-14948 1 Najeebmedia 1 Ppom For Woocommerce 2024-11-21 5.4 Medium
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
CVE-2019-14947 1 Ultimatemember 1 Ultimate Member 2024-11-21 N/A
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
CVE-2019-14946 1 Ultimatemember 1 Ultimate Member 2024-11-21 N/A
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
CVE-2019-14945 1 Ultimatemember 1 Ultimate Member 2024-11-21 N/A
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
CVE-2019-14943 1 Gitlab 1 Gitlab 2024-11-21 N/A
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.