Total
47375 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-19825 | 1 Kimai | 1 Kimai | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges. | |||||
| CVE-2020-19770 | 1 Wuzhicms | 1 Wuzhicms | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie. | |||||
| CVE-2020-19762 | 1 Carrier | 1 Webctrl System | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request. | |||||
| CVE-2020-19709 | 1 Feehi | 1 Feehicms | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload. | |||||
| CVE-2020-19704 | 1 Spring-boot-admin Project | 1 Spring-boot-admin | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML. | |||||
| CVE-2020-19703 | 1 Dzzoffice | 1 Dzzoffice | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2020-19699 | 1 Kiftd Project | 1 Kiftd | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code via the <ifram> tag in the upload file page. | |||||
| CVE-2020-19698 | 1 Ipandao | 1 Editor.md | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. | |||||
| CVE-2020-19697 | 1 Ipandao | 1 Editor.md | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter. | |||||
| CVE-2020-19683 | 1 Zzzcms | 1 Zzzcms | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php. | |||||
| CVE-2020-19660 | 1 Ipandao | 1 Editor.md | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | |||||
| CVE-2020-19643 | 1 Insma | 2 Wifi Mini Spy 1080p Hd Security Ip Camera, Wifi Mini Spy 1080p Hd Security Ip Camera Firmware | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page. | |||||
| CVE-2020-19626 | 1 Craftcms | 1 Craft Cms | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new. | |||||
| CVE-2020-19619 | 1 Mblog Project | 1 Mblog | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. | |||||
| CVE-2020-19618 | 1 Mblog Project | 1 Mblog | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. | |||||
| CVE-2020-19617 | 1 Mblog Project | 1 Mblog | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. | |||||
| CVE-2020-19616 | 1 Mblog Project | 1 Mblog | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. | |||||
| CVE-2020-19587 | 1 Idera | 1 Yellowfin Business Intelligence | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI. | |||||
| CVE-2020-19586 | 1 Yellowfinbi | 1 Business Intelligence | 2026-06-17 | N/A | 9.0 CRITICAL |
| Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI. | |||||
| CVE-2020-19554 | 1 Manageengine | 1 Opmanager | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload. | |||||
