• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-1020007

February 26, 2023 by

Dependency-Track before 3.5.1 allows XSS.

CVE-2019-1020008

February 26, 2023 by

stacktable.js before 1.0.4 allows XSS.

CVE-2019-1020010

February 26, 2023 by

Misskey before 10.102.4 allows hijacking a user’s token.

CVE-2019-10146

February 26, 2023 by

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim’s browser.

CVE-2019-1010307

February 26, 2023 by

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the “Link Tickets” feature, 3- a request to the endpoint fetches js and executes it.

CVE-2019-1010314

February 26, 2023 by

Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim’s browser, when the vulnerable repo page is loaded. The component is: repository’s description. The attack vector is: victim must navigate to public and affected repo page.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1229
  • Go to page 1230
  • Go to page 1231
  • Go to page 1232
  • Go to page 1233
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE