Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-20517 1 Frappe 1 Erpnext 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
CVE-2019-20518 1 Frappe 1 Erpnext 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CVE-2019-20519 1 Frappe 1 Erpnext 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVE-2019-20520 1 Frappe 1 Erpnext 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
CVE-2019-20514 1 Frappe 1 Erpnext 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
CVE-2018-18576 1 Incsub 1 Hustle 2020-03-19 5.0 MEDIUM 5.3 MEDIUM
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
CVE-2019-20496 1 Cpanel 1 Cpanel 2020-03-19 4.9 MEDIUM 5.5 MEDIUM
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
CVE-2019-12366 1 9folders 1 Nine 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12367 1 Blixhq 1 Bluemail 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12368 1 Edison 1 Edison Mail 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12369 1 Typeapp 1 Typeapp 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12365 1 Cloudmagic 1 Newton 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12370 1 Readdle 1 Spark 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-20497 1 Cpanel 1 Cpanel 2020-03-19 3.5 LOW 5.4 MEDIUM
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2020-6584 1 Nagios 1 Nagios 2020-03-19 4.0 MEDIUM 6.5 MEDIUM
Nagios Log Server 2.1.3 has Incorrect Access Control.
CVE-2019-20512 1 Open.edx 1 Ironwood 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
CVE-2019-19677 1 Arxes-tolina 1 Arxes-tolina 2020-03-19 4.0 MEDIUM 4.3 MEDIUM
arxes-tolina 3.0.0 allows User Enumeration.
CVE-2020-4199 1 Ibm 1 Tivoli Netcool\/omnibus 2020-03-19 4.3 MEDIUM 4.3 MEDIUM
IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910.
CVE-2019-19615 1 Sangoma 1 Freepbx 2020-03-19 3.5 LOW 4.8 MEDIUM
Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An attacker can modify the id parameter of the backup configuration screen and embed malicious XSS code via a link. When another user (such as an admin) clicks the link, the XSS payload will render and execute in the context of the victim user's account.
CVE-2019-19852 1 Sangoma 1 Freepbx 2020-03-19 3.5 LOW 4.8 MEDIUM
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4.
CVE-2019-20523 1 Ilch 1 Ilch Cms 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
CVE-2019-20524 1 Ilch 1 Ilch Cms 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.
CVE-2019-20522 1 Ilch 1 Ilch Cms 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
CVE-2020-10240 1 Joomla 1 Joomla\! 2020-03-19 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
CVE-2019-13198 1 Kyocera 2 Ecosys M5526cdw, Ecosys M5526cdw Firmware 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Stored XSS. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
CVE-2020-10113 1 Cpanel 1 Cpanel 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
CVE-2020-10114 1 Cpanel 1 Cpanel 2020-03-19 4.3 MEDIUM 6.1 MEDIUM
cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
CVE-2019-20493 1 Cpanel 1 Cpanel 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2019-13200 1 Kyocera 2 Ecosys M5526cdw, Ecosys M5526cdw Firmware 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Reflected XSS. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
CVE-2020-10242 1 Joomla 1 Joomla\! 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.
CVE-2019-10763 1 Pimcore 1 Pimcore 2020-03-18 4.0 MEDIUM 6.5 MEDIUM
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
CVE-2020-10112 1 Citrix 1 Gateway Firmware 2020-03-18 5.8 MEDIUM 5.4 MEDIUM
** DISPUTED ** Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default.
CVE-2019-14512 1 Limesurvey 1 Limesurvey 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php.
CVE-2019-19210 1 Dolibarr 1 Dolibarr 2020-03-18 3.5 LOW 5.4 MEDIUM
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
CVE-2019-19211 1 Dolibarr 1 Dolibarr 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
CVE-2019-13199 1 Kyocera 2 Ecosys M5526cdw, Ecosys M5526cdw Firmware 2020-03-18 4.3 MEDIUM 6.5 MEDIUM
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2018-10125 1 Contao 1 Contao 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
Contao before 4.5.7 has XSS in the system log.
CVE-2020-6586 1 Nagios 1 Nagios 2020-03-18 3.5 LOW 5.4 MEDIUM
Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.
CVE-2019-13167 1 Xerox 2 Phaser 3320, Phaser 3320 Firmware 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
CVE-2020-10196 1 Sygnoos 1 Popup-builder 2020-03-18 4.3 MEDIUM 6.1 MEDIUM
An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com/classes/Ajax.php. It is possible for an unauthenticated attacker to insert malicious JavaScript in several of the popup's fields by sending a request to wp-admin/admin-ajax.php with the POST action parameter of sgpb_autosave and including additional data in an allPopupData parameter, including the popup's ID (which is visible in the source of the page in which the popup is inserted) and arbitrary JavaScript which will then be executed in the browsers of visitors to that page. Because the plugin functionality automatically adds script tags to data entered into these fields, this injection will typically bypass most WAF applications.
CVE-2020-10195 1 Sygnoos 1 Popup-builder 2020-03-18 6.5 MEDIUM 6.3 MEDIUM
The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions can modify the plugin's settings to allow arbitrary roles (including subscribers) access to plugin functionality by setting the action parameter to sgpbSaveSettings, export a list of current newsletter subscribers by setting the action parameter to csv_file, or obtain system configuration information including webserver configuration and a list of installed plugins by setting the action parameter to sgpb_system_info.
CVE-2019-18576 1 Dell 1 Xtremio Management Server 2020-03-18 2.1 LOW 6.7 MEDIUM
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files may use the exposed passwords to gain access to XtremIO with the privileges of the compromised user.
CVE-2019-18577 1 Dell 1 Xtremio Management Server 2020-03-18 7.2 HIGH 6.7 MEDIUM
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain root access.
CVE-2019-3769 1 Dell 1 Wyse Management Suite 2020-03-18 3.5 LOW 6.4 MEDIUM
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious payload in the device heartbeat request. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
CVE-2019-3770 1 Dell 1 Wyse Management Suite 2020-03-18 3.5 LOW 6.4 MEDIUM
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
CVE-2018-13060 1 Easyappointments 1 Easy\!appointments 2020-03-18 5.0 MEDIUM 6.5 MEDIUM
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
CVE-2020-10079 1 Gitlab 1 Gitlab 2020-03-18 5.0 MEDIUM 5.3 MEDIUM
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.
CVE-2020-0526 1 Intel 140 Compute Stick Stck1a32wfc, Compute Stick Stck1a32wfc Firmware, Compute Stick Stck1a8lfc and 137 more 2020-03-18 4.6 MEDIUM 6.7 MEDIUM
Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html
CVE-2020-5960 1 Nvidia 1 Virtual Gpu Manager 2020-03-18 2.1 LOW 5.5 MEDIUM
NVIDIA Virtual GPU Manager contains a vulnerability in the kernel module (nvidia.ko), where a null pointer dereference may occur, which may lead to denial of service.
CVE-2019-6699 1 Fortinet 1 Fortiadc 2020-03-18 3.5 LOW 5.4 MEDIUM
An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.