• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-8939
2019-02-27
N/A
6.1 MEDIUM
data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.
CVE-2019-8938
2019-03-25
N/A
6.1 MEDIUM
VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.
CVE-2019-8937
2019-05-17
N/A
6.1 MEDIUM
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
CVE-2019-8936
2020-10-07
N/A
7.5 HIGH
NTP through 4.2.8p12 has a NULL Pointer Dereference.
CVE-2019-8935
2019-02-19
N/A
5.4 MEDIUM
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
CVE-2019-8934
2022-04-05
N/A
3.3 LOW
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
CVE-2019-8933
2019-02-20
N/A
8.8 HIGH
In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template Management, clicking on New Template, and modifying the filename from ../index.html to ../index.php.
CVE-2019-8932
2020-08-24
N/A
7.5 HIGH
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
CVE-2019-8931
2021-07-21
N/A
7.5 HIGH
Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application.
CVE-2019-8929
2019-05-17
N/A
6.1 MEDIUM
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.
« Previous 1 … 5,133 5,134 5,135 5,136 5,137 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE