• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-12461

February 26, 2023 by

Web Port 1.19.1 allows XSS via the /log type parameter.

CVE-2019-12471

February 26, 2023 by

Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

CVE-2019-12475

February 26, 2023 by

In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.

CVE-2019-12417

February 26, 2023 by

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.

CVE-2019-12427

February 26, 2023 by

Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.

CVE-2019-12442

February 26, 2023 by

An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1195
  • Go to page 1196
  • Go to page 1197
  • Go to page 1198
  • Go to page 1199
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE