Search Results (42885 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15801 1 Zyxel 18 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 15 more 2024-11-21 7.5 High
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recovery menu. Using the hardcoded cryptographic key found elsewhere in the firmware, these passwords can be decrypted. This is related to fds_sys_passDebugPasswd_ret() and fds_sys_passRecoveryPasswd_ret() in libfds.so.0.0.
CVE-2019-15782 1 Webtorrent 1 Webtorrent 2024-11-21 N/A
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
CVE-2019-15778 1 Getwooplugins 1 Additional Variation Images For Woocommerce 2024-11-21 N/A
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
CVE-2019-15777 1 Shapepress 1 Wp Dsgvo Tools 2024-11-21 N/A
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
CVE-2019-15750 1 Sitos 1 Sitos Six 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2019-15745 1 Equeshome 2 Elf Smart Plug, Elf Smart Plug Firmware 2024-11-21 N/A
The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local network can use the same key to encrypt and send commands to discover all smart plugs in a network, take over control of a device, and perform actions such as turning it on and off.
CVE-2019-15739 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.
CVE-2019-15724 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.
CVE-2019-15713 1 My Calendar Project 1 My Calendar 2024-11-21 N/A
The my-calendar plugin before 3.1.10 for WordPress has XSS.
CVE-2019-15700 1 Frappe 1 Frappe 2024-11-21 N/A
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
CVE-2019-15652 1 Nssglobal 4 Satlink 2000, Satlink 2900, Satlink 2910 and 1 more 2024-11-21 6.1 Medium
The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for error messages, leading to the ability to inject client-side code.
CVE-2019-15644 1 Zoho 1 Salesiq 2024-11-21 N/A
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
CVE-2019-15643 1 Etoilewebdesign 1 Ultimate Faq 2024-11-21 N/A
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
CVE-2019-15619 1 Nextcloud 3 Deck, Nextcloud Server, Talk 2024-11-21 4.8 Medium
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
CVE-2019-15618 1 Nextcloud 1 Nextcloud Server 2024-11-21 4.8 Medium
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
CVE-2019-15614 1 Nextcloud 1 Nextcloud 2024-11-21 5.4 Medium
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
CVE-2019-15607 1 Nodered 1 Node-red 2024-11-21 5.4 Medium
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
CVE-2019-15603 1 Seeftl Project 1 Seeftl 2024-11-21 6.1 Medium
The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directory listing.
CVE-2019-15602 1 Itwork 1 Fileview 2024-11-21 6.1 Medium
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
CVE-2019-15587 4 Canonical, Debian, Fedoraproject and 1 more 4 Ubuntu Linux, Debian Linux, Fedora and 1 more 2024-11-21 5.4 Medium
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.