• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-1020019

February 26, 2023 by

invenio-previewer before 1.0.0a12 allows XSS.

CVE-2019-10215

February 26, 2023 by

Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user’s browser.

CVE-2019-10219

February 26, 2023 by

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVE-2019-10221

February 26, 2023 by

A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.

CVE-2019-10226

February 26, 2023 by

HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI.

CVE-2019-10227

February 26, 2023 by

openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1227
  • Go to page 1228
  • Go to page 1229
  • Go to page 1230
  • Go to page 1231
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE