Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-6627 1 F5 1 Ssl Orchestrator 2019-07-10 4.3 MEDIUM 5.9 MEDIUM
On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.
CVE-2019-13186 1 1234n 1 Minicms 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.
CVE-2019-10721 1 Dotnetblogengine 1 Blogengine.net 2019-07-10 5.8 MEDIUM 6.1 MEDIUM
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
CVE-2018-12623 1 Eventum Project 1 Eventum 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
CVE-2018-12625 1 Eventum Project 1 Eventum 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
CVE-2018-12626 1 Eventum Project 1 Eventum 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
CVE-2018-12627 1 Eventum Project 1 Eventum 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter.
CVE-2018-12622 1 Eventum Project 1 Eventum 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
CVE-2016-2787 2 Puppet, Puppetlabs 2 Puppet Enterprise, Puppet Enterprise 2019-07-10 5.0 MEDIUM 5.3 MEDIUM
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.
CVE-2016-9686 1 Puppet 1 Puppet Enterprise 2019-07-10 5.0 MEDIUM 5.3 MEDIUM
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.
CVE-2015-7328 1 Puppet 1 Puppet Enterprise 2019-07-10 1.9 LOW 4.7 MEDIUM
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to obtain sensitive information via unspecified vectors.
CVE-2019-13397 1 Enhancesoft 1 Osticket 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
CVE-2019-13070 1 Cyberpowersystems 1 Powerpanel 2019-07-10 3.5 LOW 5.4 MEDIUM
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agent/action_recipient Event Action/Recipient page, the embedded code will be executed in the browser of the victim.
CVE-2019-13374 2 Dlink, Microsoft 2 Central Wifimanager, Windows 2019-07-09 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.
CVE-2019-13399 1 Fortinet 2 Fcm-mb40, Fcm-mb40 Firmware 2019-07-09 4.3 MEDIUM 5.9 MEDIUM
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.
CVE-2019-11647 1 Microfocus 1 Netiq Self Service Password Reset 2019-07-09 4.3 MEDIUM 6.1 MEDIUM
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.
CVE-2019-13072 1 Zoneminder 1 Zoneminder 2019-07-09 4.3 MEDIUM 6.1 MEDIUM
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
CVE-2019-13287 1 Glyphandcog 1 Xpdfreader 2019-07-09 4.3 MEDIUM 5.5 MEDIUM
In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to CVE-2018-16368.
CVE-2019-6639 1 F5 2 Big-ip Advanced Firewall Manager, Big-ip Policy Enforcement Manager 2019-07-09 3.5 LOW 4.8 MEDIUM
On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-site scripting (XSS) issue. This is a control plane issue only and is not accessible from the data plane. The attack requires a malicious resource administrator to store the XSS.
CVE-2019-7218 1 Citrix 1 Sharefile 2019-07-09 4.3 MEDIUM 5.9 MEDIUM
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).
CVE-2019-12930 1 Wikindx Project 1 Wikindx 2019-07-09 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via the method parameter.
CVE-2016-6329 1 Openvpn 1 Openvpn 2019-07-09 4.3 MEDIUM 5.9 MEDIUM
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
CVE-2018-14027 1 Digisol 2 Dg-hr-3300, Dg-hr-3300 Firmware 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
CVE-2019-5969 1 Weseek 1 Growi 2019-07-08 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
CVE-2018-11227 1 Monstra 1 Monstra Cms 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS 3.0.4 and earlier has XSS via index.php.
CVE-2018-12621 1 Eventum Project 1 Eventum 2019-07-08 5.8 MEDIUM 6.1 MEDIUM
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
CVE-2018-1000874 1 Cebe 1 Markdown 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distributed parsers allowing a malicious crafted script to be executed that can result in the lose of user data and sensitive user information. This attack can be exploited by crafting a three backtick wrapped payload with a character in front: L: "```<script>alert();</script>```". NOTE: This has been argued as a non-issue (see references) since it is not the parser's job to sanitize malicious code from a parsed document.
CVE-2015-2324 1 10web 1 Photo Gallery 2019-07-08 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
CVE-2019-6626 1 F5 3 Big-ip Advanced Firewall Manager, Big-ip Analytics, Big-ip Application Security Manager 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility.
CVE-2019-6625 1 F5 13 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 10 more 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
CVE-2019-13075 1 Torproject 1 Tor Browser 2019-07-08 5.0 MEDIUM 5.3 MEDIUM
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.
CVE-2019-5965 1 Joruri 1 Joruri Mail 2019-07-08 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2019-13055 1 Logitech 4 K360, K360 Firmware, Unifying Receiver and 1 more 2019-07-08 3.3 LOW 6.5 MEDIUM
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.
CVE-2019-13239 1 Glpi-project 1 Glpi 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
CVE-2016-10761 1 Logitech 10 K360, K360 Firmware, K400r and 7 more 2019-07-08 3.3 LOW 6.5 MEDIUM
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
CVE-2018-20807 1 Pulsesecure 1 Pulse Connect Secure 2019-07-08 4.3 MEDIUM 6.1 MEDIUM
An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.
CVE-2019-1577 1 Paloaltonetworks 1 Traps 2019-07-08 6.5 MEDIUM 6.3 MEDIUM
Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.
CVE-2019-13339 1 1234n 1 Minicms 2019-07-07 3.5 LOW 4.8 MEDIUM
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
CVE-2019-13341 1 1234n 1 Minicms 2019-07-07 3.5 LOW 4.8 MEDIUM
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
CVE-2019-13340 1 1234n 1 Minicms 2019-07-07 3.5 LOW 4.8 MEDIUM
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.
CVE-2017-17972 1 Archon Project 1 Archon 2019-07-07 4.3 MEDIUM 6.1 MEDIUM
packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.
CVE-2019-12842 1 Jetbrains 1 Teamcity 2019-07-05 4.3 MEDIUM 6.1 MEDIUM
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
CVE-2018-14864 1 Odoo 1 Odoo 2019-07-05 4.0 MEDIUM 6.5 MEDIUM
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.
CVE-2018-14865 1 Odoo 1 Odoo 2019-07-05 4.0 MEDIUM 6.5 MEDIUM
Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.
CVE-2017-6216 1 Novaksolutions 1 Infusionsoft-php-sdk 2019-07-05 4.3 MEDIUM 6.1 MEDIUM
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
CVE-2018-17560 1 Teamwire 1 Teamwire 2019-07-05 4.3 MEDIUM 6.1 MEDIUM
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
CVE-2018-14887 1 Odoo 1 Odoo 2019-07-05 5.8 MEDIUM 6.5 MEDIUM
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.
CVE-2018-14867 1 Odoo 1 Odoo 2019-07-05 5.0 MEDIUM 5.3 MEDIUM
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
CVE-2018-11317 1 Intelliants 1 Subrion 2019-07-05 4.3 MEDIUM 6.1 MEDIUM
Subrion CMS before 4.1.4 has XSS.
CVE-2018-20814 1 Pulsesecure 2 Pulse Connect Secure, Pulse Policy Secure 2019-07-04 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.