Vendor CVEs
Debian
All CVEs
10,468 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10785 | Med | 0.33 | 6.1 | 0.02 | Feb 13, 2020 | dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them. | ||
| CVE-2013-7371 | Med | 0.33 | 6.1 | 0.01 | Dec 11, 2019 | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) | ||
| CVE-2013-7370 | Med | 0.33 | 6.1 | 0.01 | Dec 11, 2019 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | ||
| CVE-2016-1000108 | Med | 0.33 | 6.1 | 0.01 | Dec 10, 2019 | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI… | ||
| CVE-2016-1000110 | Med | 0.33 | 6.1 | 0.05 | Nov 27, 2019 | The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests. | ||
| CVE-2013-4168 | Med | 0.33 | 6.1 | 0.01 | Nov 1, 2019 | Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. | ||
| CVE-2019-17672 | Med | 0.33 | 6.1 | 0.02 | Oct 17, 2019 | WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. | ||
| CVE-2019-17671 | Med | 0.33 | 5.3 | 0.36 | Oct 17, 2019 | In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | ||
| CVE-2017-1002201 | Med | 0.33 | 6.1 | 0.01 | Oct 15, 2019 | In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially… | ||
| CVE-2019-16935 | Med | 0.33 | 6.1 | 0.05 | Sep 28, 2019 | The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted… | ||
| CVE-2017-18635 | Med | 0.33 | 6.1 | 0.05 | Sep 25, 2019 | An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. | ||
| CVE-2019-16222 | Med | 0.33 | 6.1 | 0.02 | Sep 11, 2019 | WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. | ||
| CVE-2019-16221 | Med | 0.33 | 6.1 | 0.02 | Sep 11, 2019 | WordPress before 5.2.3 allows reflected XSS in the dashboard. | ||
| CVE-2019-16220 | Med | 0.33 | 6.1 | 0.03 | Sep 11, 2019 | In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash. | ||
| CVE-2019-16219 | Med | 0.33 | 6.1 | 0.02 | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in shortcode previews. | ||
| CVE-2019-16218 | Med | 0.33 | 6.1 | 0.02 | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in stored comments. | ||
| CVE-2019-16217 | Med | 0.33 | 6.1 | 0.02 | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. | ||
| CVE-2019-2745 | Med | 0.33 | 5.1 | 0.00 | Jul 23, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE… | ||
| CVE-2019-3902 | Med | 0.33 | 5.1 | 0.01 | Apr 22, 2019 | A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository. | ||
| CVE-2019-11454 | Med | 0.33 | 6.1 | 0.02 | Apr 22, 2019 | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is… | ||
| CVE-2019-3861 | Med | 0.33 | 5.0 | 0.05 | Mar 25, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client… | ||
| CVE-2019-3860 | Med | 0.33 | 5.0 | 0.05 | Mar 25, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | ||
| CVE-2019-3858 | Med | 0.33 | 5.0 | 0.06 | Mar 21, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | ||
| CVE-2019-1559 | Med | 0.33 | 5.9 | 0.17 | Feb 27, 2019 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0… | ||
| CVE-2019-8354 | Med | 0.33 | 5.0 | 0.02 | Feb 15, 2019 | An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow. | ||
| CVE-2018-19790 | Med | 0.33 | 6.1 | 0.01 | Dec 18, 2018 | An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the… | ||
| CVE-2018-20150 | Med | 0.33 | 6.1 | 0.04 | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. | ||
| CVE-2018-19787 | Med | 0.33 | 6.1 | 0.02 | Dec 2, 2018 | An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar… | ||
| CVE-2017-5934 | Med | 0.33 | 6.1 | 0.02 | Oct 15, 2018 | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2017-7558 | Med | 0.33 | 5.1 | 0.04 | Jul 26, 2018 | A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used… | ||
| CVE-2018-3081 | Med | 0.33 | 5.0 | 0.02 | Jul 18, 2018 | Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker… | ||
| CVE-2018-14040 | Med | 0.33 | 6.1 | 0.04 | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | ||
| CVE-2018-11408 | Med | 0.33 | 6.1 | 0.01 | Jun 13, 2018 | The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue… | ||
| CVE-2018-10102 | Med | 0.33 | 6.1 | 0.04 | Apr 16, 2018 | Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag. | ||
| CVE-2018-10101 | Med | 0.33 | 6.1 | 0.03 | Apr 16, 2018 | Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server. | ||
| CVE-2018-10100 | Med | 0.33 | 6.1 | 0.03 | Apr 16, 2018 | Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. | ||
| CVE-2018-8048 | Med | 0.33 | 6.1 | 0.02 | Mar 27, 2018 | In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. | ||
| CVE-2018-8763 | Med | 0.33 | 6.1 | 0.02 | Mar 27, 2018 | Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI. | ||
| CVE-2018-1000078 | Med | 0.33 | 6.1 | 0.03 | Mar 13, 2018 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage… | ||
| CVE-2018-1304 | Med | 0.33 | 5.9 | 0.17 | Feb 28, 2018 | The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the… | ||
| CVE-2015-6748 | Med | 0.33 | 6.1 | 0.02 | Sep 25, 2017 | Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. | ||
| CVE-2015-2749 | Med | 0.33 | 6.1 | 0.01 | Sep 13, 2017 | Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | ||
| CVE-2017-9063 | Med | 0.33 | 6.1 | 0.02 | May 18, 2017 | In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session. | ||
| CVE-2017-9061 | Med | 0.33 | 6.1 | 0.02 | May 18, 2017 | In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename. | ||
| CVE-2017-6815 | Med | 0.33 | 6.1 | 0.03 | Mar 12, 2017 | In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation. | ||
| CVE-2017-5612 | Med | 0.33 | 6.1 | 0.03 | Jan 30, 2017 | Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt. | ||
| CVE-2016-2391 | Med | 0.33 | 5.0 | 0.00 | Jun 16, 2016 | The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers. | ||
| CVE-2016-0641 | Med | 0.33 | 5.1 | 0.01 | Apr 21, 2016 | Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM. | ||
| CVE-2016-2228 | Med | 0.33 | 6.1 | 0.02 | Apr 13, 2016 | Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated… | ||
| CVE-2015-8807 | Med | 0.33 | 6.1 | 0.02 | Apr 13, 2016 | Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web… |
- risk 0.33cvss 6.1epss 0.02
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
- risk 0.33cvss 6.1epss 0.01
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
- risk 0.33cvss 6.1epss 0.01
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
- risk 0.33cvss 6.1epss 0.01
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI…
- risk 0.33cvss 6.1epss 0.05
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
- risk 0.33cvss 6.1epss 0.02
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
- risk 0.33cvss 5.3epss 0.36
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
- risk 0.33cvss 6.1epss 0.01
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially…
- risk 0.33cvss 6.1epss 0.05
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted…
- risk 0.33cvss 6.1epss 0.05
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
- risk 0.33cvss 6.1epss 0.02
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
- risk 0.33cvss 6.1epss 0.02
WordPress before 5.2.3 allows reflected XSS in the dashboard.
- risk 0.33cvss 6.1epss 0.03
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
- risk 0.33cvss 6.1epss 0.02
WordPress before 5.2.3 allows XSS in shortcode previews.
- risk 0.33cvss 6.1epss 0.02
WordPress before 5.2.3 allows XSS in stored comments.
- risk 0.33cvss 6.1epss 0.02
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
- risk 0.33cvss 5.1epss 0.00
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE…
- risk 0.33cvss 5.1epss 0.01
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
- risk 0.33cvss 6.1epss 0.02
Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is…
- risk 0.33cvss 5.0epss 0.05
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client…
- risk 0.33cvss 5.0epss 0.05
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- risk 0.33cvss 5.0epss 0.06
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- risk 0.33cvss 5.9epss 0.17
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0…
- risk 0.33cvss 5.0epss 0.02
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
- risk 0.33cvss 6.1epss 0.01
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the…
- risk 0.33cvss 6.1epss 0.04
In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
- risk 0.33cvss 6.1epss 0.02
An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar…
- risk 0.33cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.33cvss 5.1epss 0.04
A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used…
- risk 0.33cvss 5.0epss 0.02
Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker…
- risk 0.33cvss 6.1epss 0.04
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
- risk 0.33cvss 6.1epss 0.01
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue…
- risk 0.33cvss 6.1epss 0.04
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
- risk 0.33cvss 6.1epss 0.03
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
- risk 0.33cvss 6.1epss 0.03
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
- risk 0.33cvss 6.1epss 0.02
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
- risk 0.33cvss 6.1epss 0.02
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
- risk 0.33cvss 6.1epss 0.03
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage…
- risk 0.33cvss 5.9epss 0.17
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the…
- risk 0.33cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
- risk 0.33cvss 6.1epss 0.01
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
- risk 0.33cvss 6.1epss 0.02
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
- risk 0.33cvss 6.1epss 0.02
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.
- risk 0.33cvss 6.1epss 0.03
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
- risk 0.33cvss 6.1epss 0.03
Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.
- risk 0.33cvss 5.0epss 0.00
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
- risk 0.33cvss 5.1epss 0.01
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.
- risk 0.33cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated…
- risk 0.33cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web…
Page 141 of 210