Search
Total
46623 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2011-3151 | 1 Canonical | 1 Selinux | 2019-10-09 | 5.8 MEDIUM | 5.9 MEDIUM |
| The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero byte file to be allocated on any writable filesystem. | |||||
| CVE-2011-4190 | 1 Suse | 2 Suse Linux Enterprise Desktop, Suse Linux Enterprise Server | 2019-10-09 | 3.5 LOW | 5.3 MEDIUM |
| The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files). | |||||
| CVE-2009-0783 | 1 Apache | 1 Tomcat | 2019-10-09 | 4.6 MEDIUM | 4.2 MEDIUM |
| Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. | |||||
| CVE-2019-17384 | 1 Eleopard | 1 Animate It\! | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| The animate-it plugin before 2.3.4 for WordPress has XSS. | |||||
| CVE-2019-17385 | 1 Eleopard | 1 Animate It\! | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| The animate-it plugin before 2.3.5 for WordPress has XSS. | |||||
| CVE-2019-4512 | 1 Ibm | 10 Control Desk, Maximo Asset Management, Maximo For Aviation and 7 more | 2019-10-09 | 4.0 MEDIUM | 4.3 MEDIUM |
| IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554. | |||||
| CVE-2019-17271 | 1 Vbulletin | 1 Vbulletin | 2019-10-09 | 4.0 MEDIUM | 4.9 MEDIUM |
| vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter. | |||||
| CVE-2019-17378 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). | |||||
| CVE-2019-17377 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). | |||||
| CVE-2019-17379 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). | |||||
| CVE-2019-17376 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). | |||||
| CVE-2019-16416 | 1 Hrworks | 1 Hrworks | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
| HRworks 3.36.9 allows XSS via the purpose of a travel-expense report. | |||||
| CVE-2019-16417 | 1 Hrworks | 1 Hrworks | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
| HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report. | |||||
| CVE-2019-6648 | 2 F5, Redhat | 2 Container Ingress Service, Openshift | 2019-10-09 | 1.9 LOW | 4.4 MEDIUM |
| On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Declaration. | |||||
| CVE-2019-6653 | 1 F5 | 1 Big-iq Centralized Management | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
| There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles. | |||||
| CVE-2019-6651 | 1 F5 | 16 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 13 more | 2019-10-09 | 5.0 MEDIUM | 5.3 MEDIUM |
| In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request. | |||||
| CVE-2019-17368 | 1 S-cms | 1 S-cms | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter. | |||||
| CVE-2019-17380 | 1 Cpanel | 1 Cpanel | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). | |||||
| CVE-2019-16931 | 1 Themeisle | 1 Visualizer | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization. | |||||
| CVE-2019-16198 | 1 Kslabs | 1 Ksweb | 2019-10-09 | 4.0 MEDIUM | 6.5 MEDIUM |
| KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter. | |||||
| CVE-2019-15499 | 2 Apple, Hackmd | 2 Safari, Codimd | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. | |||||
| CVE-2019-4342 | 1 Ibm | 1 Cognos Analytics | 2019-10-09 | 3.5 LOW | 5.4 MEDIUM |
| IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 161421. | |||||
| CVE-2019-15750 | 1 Sitos | 1 Sitos Six | 2019-10-09 | 4.3 MEDIUM | 6.1 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||||
| CVE-2019-15749 | 1 Sitos | 1 Sitos Six | 2019-10-09 | 4.3 MEDIUM | 6.5 MEDIUM |
| SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address. | |||||
| CVE-2016-1144 | 1 Websquare | 1 Job-cube | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2019-15041 | 1 Jetbrains | 1 Youtrack | 2019-10-08 | 5.8 MEDIUM | 6.1 MEDIUM |
| JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere. | |||||
| CVE-2019-11656 | 1 Hp | 1 Arcsight Logger | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). | |||||
| CVE-2019-14957 | 1 Jetbrains | 1 Vim | 2019-10-08 | 5.0 MEDIUM | 5.3 MEDIUM |
| The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository. | |||||
| CVE-2019-12737 | 1 Jetbrains | 1 Ktor | 2019-10-08 | 5.0 MEDIUM | 5.3 MEDIUM |
| UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. | |||||
| CVE-2019-17213 | 1 Webarxsecurity | 1 Webarx | 2019-10-08 | 4.3 MEDIUM | 6.1 MEDIUM |
| The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header. | |||||
| CVE-2019-17121 | 1 Vanderbilt | 1 Redcap | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values. | |||||
| CVE-2019-17225 | 1 Intelliants | 1 Subrion | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | |||||
| CVE-2019-17226 | 1 Cmsmadesimple | 1 Cms Made Simple | 2019-10-08 | 3.5 LOW | 4.8 MEDIUM |
| CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field. | |||||
| CVE-2019-16332 | 1 Api Bearer Auth Project | 1 Api Bearer Auth | 2019-10-08 | 4.3 MEDIUM | 6.1 MEDIUM |
| In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS. | |||||
| CVE-2019-14955 | 1 Jetbrains | 1 Hub | 2019-10-08 | 5.0 MEDIUM | 5.3 MEDIUM |
| In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented. | |||||
| CVE-2017-18102 | 1 Atlassian | 1 Jira | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup. | |||||
| CVE-2019-17203 | 1 Teampass | 1 Teampass | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. | |||||
| CVE-2019-17204 | 1 Teampass | 1 Teampass | 2019-10-08 | 3.5 LOW | 5.4 MEDIUM |
| TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. | |||||
| CVE-2019-17205 | 1 Teampass | 1 Teampass | 2019-10-08 | 4.3 MEDIUM | 6.1 MEDIUM |
| TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. | |||||
| CVE-2018-1000547 | 1 Corebos | 1 Corebos | 2019-10-08 | 5.0 MEDIUM | 5.3 MEDIUM |
| coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no permissions to. . | |||||
| CVE-2018-7274 | 1 Quarx Cms Project | 1 Quarx Cms | 2019-10-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name). | |||||
| CVE-2019-17074 | 1 Xunruicms | 1 Xunruicms | 2019-10-07 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area. | |||||
| CVE-2019-9312 | 1 Google | 1 Android | 2019-10-07 | 2.1 LOW | 5.5 MEDIUM |
| In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78288018 | |||||
| CVE-2019-9356 | 1 Google | 1 Android | 2019-10-07 | 1.9 LOW | 5.0 MEDIUM |
| In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111699773 | |||||
| CVE-2019-9246 | 1 Google | 1 Android | 2019-10-07 | 1.9 LOW | 5.0 MEDIUM |
| In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120428637 | |||||
| CVE-2018-19975 | 1 Virustotal | 1 Yara | 2019-10-06 | 7.1 HIGH | 5.5 MEDIUM |
| In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD. | |||||
| CVE-2018-19976 | 1 Virustotal | 1 Yara | 2019-10-06 | 4.3 MEDIUM | 5.5 MEDIUM |
| In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine. | |||||
| CVE-2019-11747 | 1 Mozilla | 2 Firefox, Firefox Esr | 2019-10-05 | 4.3 MEDIUM | 6.5 MEDIUM |
| The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-load list also have their HSTS setting removed. On the next visit to that site if the user specifies an http: URL rather than secure https: they will not be protected by the pre-loaded HSTS setting. After that visit the site's HSTS setting will be restored. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. | |||||
| CVE-2019-8290 | 1 Online Store System Project | 1 Online Store System | 2019-10-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected. | |||||
| CVE-2019-11744 | 1 Mozilla | 3 Firefox, Firefox Esr, Thunderbird | 2019-10-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as it does for other elements. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. | |||||
