• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-10238

February 26, 2023 by

Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter.

CVE-2019-10241

February 26, 2023 by

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.

CVE-2019-10254

February 26, 2023 by

In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.

CVE-2019-10260

February 26, 2023 by

Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format).

CVE-2019-10261

February 26, 2023 by

CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the “Name Server 1” and “Name Server 2” fields via a “DNS Functions” “Edit Nameservers IPs” action.

CVE-2019-10263

February 26, 2023 by

An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin’s cookie and take over the account.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1226
  • Go to page 1227
  • Go to page 1228
  • Go to page 1229
  • Go to page 1230
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE