Search
Total
46623 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-20902 | 1 Cpanel | 1 Cpanel | 2019-08-02 | 2.1 LOW | 5.5 MEDIUM |
| cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | |||||
| CVE-2018-20903 | 1 Cpanel | 1 Cpanel | 2019-08-02 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421). | |||||
| CVE-2018-20912 | 1 Cpanel | 1 Cpanel | 2019-08-02 | 6.5 MEDIUM | 6.3 MEDIUM |
| cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | |||||
| CVE-2018-20913 | 1 Cpanel | 1 Cpanel | 2019-08-02 | 3.5 LOW | 4.9 MEDIUM |
| cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | |||||
| CVE-2018-20881 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | |||||
| CVE-2018-20879 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 6.5 MEDIUM | 6.3 MEDIUM |
| cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). | |||||
| CVE-2018-20878 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | |||||
| CVE-2018-20877 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | |||||
| CVE-2018-20876 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | |||||
| CVE-2018-20875 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | |||||
| CVE-2018-20884 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | |||||
| CVE-2018-20885 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 5.0 MEDIUM | 5.3 MEDIUM |
| cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | |||||
| CVE-2018-20910 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). | |||||
| CVE-2018-20915 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). | |||||
| CVE-2018-20916 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | |||||
| CVE-2018-20917 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 2.1 LOW | 5.5 MEDIUM |
| cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | |||||
| CVE-2018-20918 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | |||||
| CVE-2018-20919 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | |||||
| CVE-2018-20920 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | |||||
| CVE-2018-20921 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | |||||
| CVE-2018-20922 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | |||||
| CVE-2018-20923 | 1 Cpanel | 1 Cpanel | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | |||||
| CVE-2019-1020005 | 1 Inveniosoftware | 1 Invenio-communities | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| invenio-communities before 1.0.0a20 allows XSS. | |||||
| CVE-2019-13607 | 1 Opera | 1 Mini | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigation to a javascript: URL. | |||||
| CVE-2019-1020003 | 1 Inveniosoftware | 1 Invenio-records | 2019-08-01 | 3.5 LOW | 5.4 MEDIUM |
| invenio-records before 1.2.2 allows XSS. | |||||
| CVE-2019-1020006 | 1 Inveniosoftware | 1 Invenio-app | 2019-08-01 | 5.8 MEDIUM | 6.1 MEDIUM |
| invenio-app before 1.1.1 allows host header injection. | |||||
| CVE-2019-1020016 | 1 Ash-aio Project | 1 Ash-aio | 2019-08-01 | 5.8 MEDIUM | 6.1 MEDIUM |
| ASH-AIO before 2.0.0.3 allows an open redirect. | |||||
| CVE-2015-9288 | 1 Unity | 1 Web Player | 2019-08-01 | 4.0 MEDIUM | 6.5 MEDIUM |
| The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials | |||||
| CVE-2019-13584 | 1 Fanucamerica | 1 Robotics Virtual Robot Controller | 2019-08-01 | 5.0 MEDIUM | 5.3 MEDIUM |
| The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request. | |||||
| CVE-2018-14037 | 1 Progress | 1 Kendo Ui | 2019-08-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the editor, the payload gets executed. Furthermore, if the payload is reflected at any other resource that does rely on the sanitisation of the editor itself, the JavaScript payload will be executed in the context of the application. This allows attackers (in the worst case) to take over user sessions. | |||||
| CVE-2019-1020019 | 1 Inveniosoftware | 1 Invenio-previewer | 2019-07-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| invenio-previewer before 1.0.0a12 allows XSS. | |||||
| CVE-2019-14327 | 1 Custom Simple Rss Project | 1 Custom Simple Rss | 2019-07-31 | 4.3 MEDIUM | 6.5 MEDIUM |
| A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings. | |||||
| CVE-2019-1020008 | 1 Stacktable.js Project | 1 Stacktable.js | 2019-07-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| stacktable.js before 1.0.4 allows XSS. | |||||
| CVE-2019-14286 | 1 Misp | 1 Misp | 2019-07-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability. | |||||
| CVE-2019-7280 | 1 Primasystems | 1 Flexair | 2019-07-31 | 4.0 MEDIUM | 4.3 MEDIUM |
| Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication. | |||||
| CVE-2018-20870 | 1 Cpanel | 1 Cpanel | 2019-07-31 | 2.1 LOW | 5.5 MEDIUM |
| The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | |||||
| CVE-2018-20864 | 1 Cpanel | 1 Cpanel | 2019-07-31 | 6.4 MEDIUM | 6.5 MEDIUM |
| cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | |||||
| CVE-2019-10263 | 1 Ahsay | 1 Cloud Backup Suite | 2019-07-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the account. | |||||
| CVE-2019-13414 | 1 Boiteasite | 1 Rencontre | 2019-07-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php. | |||||
| CVE-2019-6002 | 1 Central Dogma Project | 1 Central Dogma | 2019-07-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2018-1000169 | 1 Jenkins | 1 Jenkins | 2019-07-31 | 5.0 MEDIUM | 5.3 MEDIUM |
| An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker-specified name by sending a CLI command to Jenkins. | |||||
| CVE-2019-11727 | 1 Mozilla | 1 Firefox | 2019-07-30 | 5.0 MEDIUM | 5.3 MEDIUM |
| A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68. | |||||
| CVE-2018-20867 | 1 Cpanel | 1 Cpanel | 2019-07-30 | 5.8 MEDIUM | 6.1 MEDIUM |
| cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). | |||||
| CVE-2019-14403 | 1 Cpanel | 1 Cpanel | 2019-07-30 | 4.3 MEDIUM | 4.3 MEDIUM |
| cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). | |||||
| CVE-2018-20866 | 1 Cpanel | 1 Cpanel | 2019-07-30 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | |||||
| CVE-2018-20868 | 1 Cpanel | 1 Cpanel | 2019-07-30 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | |||||
| CVE-2018-19311 | 1 Centreon | 1 Centreon | 2019-07-30 | 3.5 LOW | 5.4 MEDIUM |
| Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen. | |||||
| CVE-2018-19280 | 1 Centreon | 1 Centreon | 2019-07-30 | 4.3 MEDIUM | 6.1 MEDIUM |
| Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro. | |||||
| CVE-2015-7672 | 1 Centreon | 1 Centreon | 2019-07-30 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27). | |||||
| CVE-2019-14406 | 1 Cpanel | 1 Cpanel | 2019-07-30 | 4.3 MEDIUM | 6.1 MEDIUM |
| cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | |||||
