• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-7348

February 26, 2023 by

Self – Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable ‘username’ parameter value in the view user (user.php) because proper filtration is omitted.

CVE-2019-7349

February 26, 2023 by

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable ‘newMonitor[V4LCapturesPerFrame]’ parameter value in the view monitor (monitor.php) because proper filtration is omitted.

CVE-2019-7352

February 26, 2023 by

Self – Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view ‘state’ (aka Run State) (state.php) does no input validation to the value supplied to the ‘New State’ (aka newState) field, allowing an attacker to execute HTML or JavaScript code.

CVE-2019-7356

February 26, 2023 by

Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.

CVE-2019-7295

February 26, 2023 by

typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.

CVE-2019-7296

February 26, 2023 by

typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 996
  • Go to page 997
  • Go to page 998
  • Go to page 999
  • Go to page 1000
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE