• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-14996

February 26, 2023 by

The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

CVE-2019-15007

February 26, 2023 by

The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.

CVE-2019-15008

February 26, 2023 by

The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.

CVE-2019-14928

February 26, 2023 by

An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.

CVE-2019-14945

February 26, 2023 by

The ultimate-member plugin before 2.0.54 for WordPress has XSS.

CVE-2019-14946

February 26, 2023 by

The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1154
  • Go to page 1155
  • Go to page 1156
  • Go to page 1157
  • Go to page 1158
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE