• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-15700

February 26, 2023 by

public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted “changed value of” text.

CVE-2019-15618

February 26, 2023 by

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

CVE-2019-15619

February 26, 2023 by

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

CVE-2019-15643

February 26, 2023 by

The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

CVE-2019-15644

February 26, 2023 by

The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.

CVE-2019-1565

February 26, 2023 by

The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to inject arbitrary JavaScript or HTML.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1142
  • Go to page 1143
  • Go to page 1144
  • Go to page 1145
  • Go to page 1146
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE