Search Results (42958 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-16195 1 Centreon 1 Centreon 2024-11-21 6.1 Medium
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
CVE-2019-16193 1 Esri 1 Arcgis Enterprise 2024-11-21 5.4 Medium
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
CVE-2019-16182 1 Limesurvey 1 Limesurvey 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
CVE-2019-16178 1 Limesurvey 1 Limesurvey 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.
CVE-2019-16173 1 Limesurvey 1 Limesurvey 2024-11-21 5.4 Medium
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
CVE-2019-16172 1 Limesurvey 1 Limesurvey 2024-11-21 5.4 Medium
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
CVE-2019-16171 1 Jetbrains 1 Youtrack 2024-11-21 6.1 Medium
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
CVE-2019-16156 1 Fortinet 1 Fortiweb 2024-11-21 6.1 Medium
An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross Site Scripting attack (XSS).
CVE-2019-16154 1 Fortinet 1 Fortiauthenticator 2024-11-21 6.1 Medium
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.
CVE-2019-16153 1 Fortinet 1 Fortisiem 2024-11-21 9.8 Critical
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
CVE-2019-16150 1 Fortinet 1 Forticlient 2024-11-21 5.5 Medium
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key.
CVE-2019-16148 1 Sakailms 1 Sakai 2024-11-21 6.1 Medium
Sakai through 12.6 allows XSS via a chat user name.
CVE-2019-16147 1 Liferay 1 Liferay Portal 2024-11-21 6.1 Medium
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
CVE-2019-16146 1 Getgophish 1 Gophish 2024-11-21 4.8 Medium
Gophish through 0.8.0 allows XSS via a username.
CVE-2019-16145 1 Padrinorb 1 Padrino-contrib 2024-11-21 6.1 Medium
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
CVE-2019-16130 1 Hgw168cc 1 Yii-cms 2024-11-21 6.1 Medium
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
CVE-2019-16126 1 Getgrav 1 Grav Cms 2024-11-21 6.1 Medium
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
CVE-2019-16118 1 10web 1 Photo Gallery 2024-11-21 6.1 Medium
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
CVE-2019-16117 1 10web 1 Photo Gallery 2024-11-21 6.1 Medium
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
CVE-2019-16104 1 Silver-peak 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware 2024-11-21 6.1 Medium
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.