• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-15652

February 26, 2023 by

The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn’t properly sanitize input for error messages, leading to the ability to inject client-side code.

CVE-2019-15586

February 26, 2023 by

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

CVE-2019-15587

February 26, 2023 by

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVE-2019-15602

February 26, 2023 by

The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.

CVE-2019-15603

February 26, 2023 by

The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directory listing.

CVE-2019-15607

February 26, 2023 by

A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1143
  • Go to page 1144
  • Go to page 1145
  • Go to page 1146
  • Go to page 1147
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE