• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-14472

February 26, 2023 by

Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.

CVE-2019-14478

February 26, 2023 by

AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user’s input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript code in the context of the user’s browser if the victim opens or searches for a node whose “Display Name” contains an XSS payload.

CVE-2019-14406

February 26, 2023 by

cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).

CVE-2019-14415

February 26, 2023 by

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user’s browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.

CVE-2019-14427

February 26, 2023 by

XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.

CVE-2019-14364

February 26, 2023 by

An XSS vulnerability in the “Email Subscribers & Newsletters” plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1166
  • Go to page 1167
  • Go to page 1168
  • Go to page 1169
  • Go to page 1170
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE