Export limit exceeded: 88023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (88023 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-17630 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | 4.8 Medium |
| CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen. | ||||
| CVE-2019-17629 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | 4.8 Medium |
| CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen. | ||||
| CVE-2019-17625 | 1 Rambox | 1 Rambox | 2024-11-21 | 9.0 Critical |
| There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element. | ||||
| CVE-2019-17624 | 1 X.org | 1 X Server | 2024-11-21 | 7.8 High |
| "" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact. Note: It is disputed if the X.Org X Server is involved or if there is a stack overflow. | ||||
| CVE-2019-17611 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 6.1 Medium |
| HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter. | ||||
| CVE-2019-17610 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 6.1 Medium |
| HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter. | ||||
| CVE-2019-17609 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 6.1 Medium |
| HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter. | ||||
| CVE-2019-17608 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 6.1 Medium |
| HongCMS 3.0.0 has XSS via the install/index.php dbname parameter. | ||||
| CVE-2019-17607 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 6.1 Medium |
| HongCMS 3.0.0 has XSS via the install/index.php servername parameter. | ||||
| CVE-2019-17606 | 1 Hexo-admin Project | 1 Hexo-admin | 2024-11-21 | 6.1 Medium |
| The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post. | ||||
| CVE-2019-17603 | 1 Asus | 1 Aura Sync | 2024-11-21 | 7.8 High |
| Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption. | ||||
| CVE-2019-17601 | 1 Minishare Project | 1 Minishare | 2024-11-21 | 9.8 Critical |
| In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19862 and CVE-2018-19861. NOTE: this product is discontinued. | ||||
| CVE-2019-17599 | 1 Expresstech | 1 Quiz And Survey Master | 2024-11-21 | 6.1 Medium |
| The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL. | ||||
| CVE-2019-17583 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 7.5 High |
| idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer. | ||||
| CVE-2019-17581 | 1 Dormsystem Project | 1 Dormsystem | 2024-11-21 | 6.1 Medium |
| tonyy dormsystem through 1.3 allows DOM XSS. | ||||
| CVE-2019-17579 | 1 Sonarsource | 1 Sonarqube | 2024-11-21 | 6.1 Medium |
| SonarSource SonarQube before 7.8 has XSS in project links on account/projects. | ||||
| CVE-2019-17578 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-11-21 | 5.4 Medium |
| An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field. | ||||
| CVE-2019-17577 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-11-21 | 5.4 Medium |
| An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field. | ||||
| CVE-2019-17576 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-11-21 | 5.4 Medium |
| An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field. | ||||
| CVE-2019-17575 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | 7.2 High |
| A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .jpg file, and then change the file's base name to filename.ph and change the file's extension to p. Because of concatenation, the name is then treated as filename.php.) At the result, remote attackers can execute arbitrary PHP code. | ||||