Search Results (42958 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-8950 1 Dasannetworks 2 H665, H665 Firmware 2024-11-21 N/A
The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.
CVE-2019-8947 1 Zimbra 1 Collaboration Server 2024-11-21 6.1 Medium
Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.
CVE-2019-8946 1 Zimbra 1 Collaboration Server 2024-11-21 6.1 Medium
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
CVE-2019-8945 1 Zimbra 1 Collaboration Server 2024-11-21 6.1 Medium
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
CVE-2019-8939 1 Tautulli 1 Tautulli 2024-11-21 N/A
data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.
CVE-2019-8938 1 Vertrigoserv Project 1 Vertrigoserv 2024-11-21 N/A
VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.
CVE-2019-8937 1 Digitaldruid 1 Hoteldruid 2024-11-21 N/A
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
CVE-2019-8935 1 O-dyn 1 Collabtive 2024-11-21 N/A
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
CVE-2019-8929 1 Zohocorp 1 Manageengine Netflow Analyzer 2024-11-21 N/A
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.
CVE-2019-8928 1 Zohocorp 1 Manageengine Netflow Analyzer 2024-11-21 N/A
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.
CVE-2019-8927 1 Zohocorp 1 Manageengine Netflow Analyzer 2024-11-21 N/A
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep_Type, schDesc, schName, schSource, selectDeviceDone, task, val10, and val11.
CVE-2019-8926 1 Zohocorp 1 Manageengine Netflow Analyzer 2024-11-21 N/A
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.
CVE-2019-8924 1 Apachefriends 1 Xampp 2024-11-21 N/A
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
CVE-2019-8920 1 Apachefriends 1 Xampp 2024-11-21 N/A
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
CVE-2019-8911 1 Wtcms Project 1 Wtcms 2024-11-21 N/A
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
CVE-2019-8813 3 Apple, Redhat, Webkitgtk 8 Icloud, Ipados, Iphone Os and 5 more 2024-11-21 6.1 Medium
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
CVE-2019-8764 3 Apple, Redhat, Webkitgtk 3 Watchos, Enterprise Linux, Webkitgtk\+ 2024-11-21 6.1 Medium
A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
CVE-2019-8762 1 Apple 6 Icloud, Ipad Os, Iphone Os and 3 more 2024-11-21 6.1 Medium
A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
CVE-2019-8753 1 Apple 4 Iphone Os, Mac Os X, Tvos and 1 more 2024-11-21 6.1 Medium
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. Processing maliciously crafted web content may lead to a cross site scripting attack.
CVE-2019-8719 3 Apple, Redhat, Webkitgtk 4 Icloud, Itunes, Enterprise Linux and 1 more 2024-11-21 6.1 Medium
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.