• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-17070

February 26, 2023 by

The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer.

CVE-2019-17071

February 26, 2023 by

The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.

CVE-2019-17074

February 26, 2023 by

An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.

CVE-2019-17091

February 26, 2023 by

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

CVE-2019-17092

February 26, 2023 by

An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.

CVE-2019-17000

February 26, 2023 by

An object tag with a data URI did not correctly inherit the document’s Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document’s policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1109
  • Go to page 1110
  • Go to page 1111
  • Go to page 1112
  • Go to page 1113
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE