|
221471
|
4.8 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration fe…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20416
|
2024-11-21 13:38 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221472
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected version…
|
CWE-352
Origin Validation Error
|
CVE-2019-20415
|
2024-11-21 13:38 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221473
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20414
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221474
|
7.5 |
HIGH
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa pa…
|
NVD-CWE-noinfo
|
CVE-2019-20413
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221475
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerabi…
|
CWE-287
Improper Authentication
|
CVE-2019-20412
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221476
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before …
|
CWE-352
Origin Validation Error
|
CVE-2019-20411
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221477
|
6.5 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The aff…
|
NVD-CWE-noinfo
|
CVE-2019-20410
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221478
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_software_data_center jira
|
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a ser…
|
CWE-74
Injection
|
CVE-2019-20409
|
2024-11-21 13:38 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221479
|
8.1 |
HIGH
Network
|
intelliants
|
subrion
|
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenti…
|
CWE-352
Origin Validation Error
|
CVE-2019-20390
|
2024-11-21 13:38 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221480
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion
|
An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within mul…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20389
|
2024-11-21 13:38 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|