CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.
The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting
Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
