|
219461
|
6.1 |
MEDIUM
Network
|
tophub
|
toplist
|
TopList before 2019-09-03 allows XSS via a title.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20377
|
2024-11-21 13:38 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219462
|
6.1 |
MEDIUM
Network
|
ganglia
|
ganglia-web
|
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20379
|
2024-11-21 13:38 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219463
|
6.1 |
MEDIUM
Network
|
ganglia
|
ganglia-web
|
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20378
|
2024-11-21 13:38 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219464
|
6.1 |
MEDIUM
Network
|
psi
|
electronic_logbook
|
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20376
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219465
|
6.1 |
MEDIUM
Network
|
psi
|
electronic_logbook
|
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20375
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219466
|
9.6 |
CRITICAL
Network
|
typora
|
typora
|
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20374
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219467
|
7.8 |
HIGH
Local
|
debian ltsp
|
debian_linux ldm
|
LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support for Bourne shell syntax. This is related to a run-x-…
|
NVD-CWE-noinfo
|
CVE-2019-20373
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219468
|
7.8 |
HIGH
Local
|
keepass
|
keepass
|
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-20184
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219469
|
7.2 |
HIGH
Network
|
employee_records_system_project
|
employee_records_system
|
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to all…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-20183
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219470
|
4.8 |
MEDIUM
Network
|
fooplugins
|
foogallery
|
The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20182
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|