VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2019-10785MedFeb 13, 2020
    risk 0.33cvss 6.1epss 0.02

    dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.

  • CVE-2013-7371MedDec 11, 2019
    risk 0.33cvss 6.1epss 0.01

    node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)

  • CVE-2013-7370MedDec 11, 2019
    risk 0.33cvss 6.1epss 0.01

    node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware

  • CVE-2016-1000108MedDec 10, 2019
    risk 0.33cvss 6.1epss 0.01

    yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI…

  • CVE-2016-1000110MedNov 27, 2019
    risk 0.33cvss 6.1epss 0.05

    The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

  • CVE-2013-4168MedNov 1, 2019
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.

  • CVE-2019-17672MedOct 17, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

  • CVE-2019-17671MedOct 17, 2019
    risk 0.33cvss 5.3epss 0.36

    In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

  • CVE-2017-1002201MedOct 15, 2019
    risk 0.33cvss 6.1epss 0.01

    In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially…

  • CVE-2019-16935MedSep 28, 2019
    risk 0.33cvss 6.1epss 0.05

    The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted…

  • CVE-2017-18635MedSep 25, 2019
    risk 0.33cvss 6.1epss 0.05

    An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

  • CVE-2019-16222MedSep 11, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

  • CVE-2019-16221MedSep 11, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.3 allows reflected XSS in the dashboard.

  • CVE-2019-16220MedSep 11, 2019
    risk 0.33cvss 6.1epss 0.03

    In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.

  • CVE-2019-16219MedSep 11, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.3 allows XSS in shortcode previews.

  • CVE-2019-16218MedSep 11, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.3 allows XSS in stored comments.

  • CVE-2019-16217MedSep 11, 2019
    risk 0.33cvss 6.1epss 0.02

    WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

  • CVE-2019-2745MedJul 23, 2019
    risk 0.33cvss 5.1epss 0.00

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE…

  • CVE-2019-3902MedApr 22, 2019
    risk 0.33cvss 5.1epss 0.01

    A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.

  • CVE-2019-11454MedApr 22, 2019
    risk 0.33cvss 6.1epss 0.02

    Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is…

  • CVE-2019-3861MedMar 25, 2019
    risk 0.33cvss 5.0epss 0.05

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client…

  • CVE-2019-3860MedMar 25, 2019
    risk 0.33cvss 5.0epss 0.05

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

  • CVE-2019-3858MedMar 21, 2019
    risk 0.33cvss 5.0epss 0.06

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

  • CVE-2019-1559MedFeb 27, 2019
    risk 0.33cvss 5.9epss 0.17

    If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0…

  • CVE-2019-8354MedFeb 15, 2019
    risk 0.33cvss 5.0epss 0.02

    An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.

  • CVE-2018-19790MedDec 18, 2018
    risk 0.33cvss 6.1epss 0.01

    An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the…

  • CVE-2018-20150MedDec 14, 2018
    risk 0.33cvss 6.1epss 0.04

    In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

  • CVE-2018-19787MedDec 2, 2018
    risk 0.33cvss 6.1epss 0.02

    An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar…

  • CVE-2017-5934MedOct 15, 2018
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2017-7558MedJul 26, 2018
    risk 0.33cvss 5.1epss 0.04

    A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used…

  • CVE-2018-3081MedJul 18, 2018
    risk 0.33cvss 5.0epss 0.02

    Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker…

  • CVE-2018-14040MedJul 13, 2018
    risk 0.33cvss 6.1epss 0.04

    In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

  • CVE-2018-11408MedJun 13, 2018
    risk 0.33cvss 6.1epss 0.01

    The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue…

  • CVE-2018-10102MedApr 16, 2018
    risk 0.33cvss 6.1epss 0.04

    Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.

  • CVE-2018-10101MedApr 16, 2018
    risk 0.33cvss 6.1epss 0.03

    Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

  • CVE-2018-10100MedApr 16, 2018
    risk 0.33cvss 6.1epss 0.03

    Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

  • CVE-2018-8048MedMar 27, 2018
    risk 0.33cvss 6.1epss 0.02

    In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

  • CVE-2018-8763MedMar 27, 2018
    risk 0.33cvss 6.1epss 0.02

    Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.

  • CVE-2018-1000078MedMar 13, 2018
    risk 0.33cvss 6.1epss 0.03

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage…

  • CVE-2018-1304MedFeb 28, 2018
    risk 0.33cvss 5.9epss 0.17

    The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the…

  • CVE-2015-6748MedSep 25, 2017
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.

  • CVE-2015-2749MedSep 13, 2017
    risk 0.33cvss 6.1epss 0.01

    Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

  • CVE-2017-9063MedMay 18, 2017
    risk 0.33cvss 6.1epss 0.02

    In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.

  • CVE-2017-9061MedMay 18, 2017
    risk 0.33cvss 6.1epss 0.02

    In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

  • CVE-2017-6815MedMar 12, 2017
    risk 0.33cvss 6.1epss 0.03

    In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

  • CVE-2017-5612MedJan 30, 2017
    risk 0.33cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

  • CVE-2016-2391MedJun 16, 2016
    risk 0.33cvss 5.0epss 0.00

    The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.

  • CVE-2016-0641MedApr 21, 2016
    risk 0.33cvss 5.1epss 0.01

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.

  • CVE-2016-2228MedApr 13, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated…

  • CVE-2015-8807MedApr 13, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web…

Page 141 of 210