VendorsDebiandebian_linux10.0
Vulnerabilities

Debian Debian Linux 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3432CVEs
CVE-2016-1000110
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
Published 2019-11-27 · Modified
6.1EPSS 0.045
CVE-2021-28957
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
Published 2021-03-21 · Modified
6.1EPSS 0.040
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Published 2020-12-03 · Modified
6.1EPSS 0.040
CVE-2020-13596
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
Published 2020-06-03 · Modified
6.1EPSS 0.029
CVE-2020-25706
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
Published 2020-11-12 · Modified
6.1EPSS 0.028
CVE-2020-12625
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
Published 2020-05-04 · Modified
6.1EPSS 0.028
CVE-2019-20042
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Published 2019-12-27 · Modified
6.1EPSS 0.028
CVE-2022-31160
jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label
Published 2022-07-20 · Modified
6.1EPSS 0.026
CVE-2020-28038
WordPress before 5.5.2 allows stored XSS via post slugs.
Published 2020-10-31 · Modified
6.1EPSS 0.026
CVE-2019-16220
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
Published 2019-09-11 · Modified
6.1EPSS 0.026
CVE-2021-40732
XMP Toolkit SDK Null Pointer Dereference
Published 2021-10-13 · Modified
6.1EPSS 0.024
CVE-2020-15169
XSS in Action View
Published 2020-09-11 · Modified
6.1EPSS 0.024
CVE-2020-15157
containerd can be coerced into leaking credentials during image pull
Published 2020-10-16 · Modified
6.1EPSS 0.023
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
Published 2020-04-24 · Modified
6.1EPSS 0.023
CVE-2020-23226
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
Published 2021-08-27 · Modified
6.1EPSS 0.023
CVE-2019-16222
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
Published 2019-09-11 · Modified
6.1EPSS 0.022
CVE-2020-11029
Cross-site scripting in stats method (object cache) in WordPress
Published 2020-04-30 · Modified
6.1EPSS 0.021
CVE-2020-15562
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
Published 2020-07-06 · Modified
6.1EPSS 0.021
CVE-2019-17016
When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Published 2020-01-08 · Modified
6.1EPSS 0.020
CVE-2019-17022
When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Published 2020-01-08 · Modified
6.1EPSS 0.020
CVE-2021-21330
Open redirect vulnerability in aiohttp
Published 2021-02-26 · Modified
6.1EPSS 0.019
CVE-2019-16219
WordPress before 5.2.3 allows XSS in shortcode previews.
Published 2019-09-11 · Modified
6.1EPSS 0.019
CVE-2019-16218
WordPress before 5.2.3 allows XSS in stored comments.
Published 2019-09-11 · Modified
6.1EPSS 0.018
CVE-2019-16221
WordPress before 5.2.3 allows reflected XSS in the dashboard.
Published 2019-09-11 · Modified
6.1EPSS 0.018
CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
Published 2019-10-17 · Modified
6.1EPSS 0.018
CVE-2022-22577
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
Published 2022-05-26 · Modified
6.1EPSS 0.018
CVE-2021-39191
URL Redirection to Untrusted Site ('Open Redirect') in mod_auth_openidc
Published 2021-09-03 · Modified
6.1EPSS 0.017
CVE-2020-28034
WordPress before 5.5.2 allows XSS associated with global variables.
Published 2020-10-31 · Modified
6.1EPSS 0.017
CVE-2020-15677
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
Published 2020-10-01 · Modified
6.1EPSS 0.017
CVE-2022-27777
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
Published 2022-05-26 · Modified
6.1EPSS 0.016
CVE-2013-1951
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Published 2019-10-31 · Modified
6.1EPSS 0.016
CVE-2020-15676
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
Published 2020-10-01 · Modified
6.1EPSS 0.016
CVE-2019-19709
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Published 2019-12-11 · Modified
6.1EPSS 0.016
CVE-2019-16217
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Published 2019-09-11 · Modified
6.1EPSS 0.015
CVE-2021-45085
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
Published 2021-12-16 · Modified
6.1EPSS 0.015
CVE-2021-45087
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
Published 2021-12-16 · Modified
6.1EPSS 0.015
CVE-2020-35479
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.
Published 2020-12-18 · Modified
6.1EPSS 0.015
CVE-2021-30890
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
Published 2021-08-24 · Modified
6.1EPSS 0.015
CVE-2013-7371
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
Published 2019-12-11 · Modified
6.1EPSS 0.014
CVE-2021-45088
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
Published 2021-12-16 · Modified
6.1EPSS 0.014
← Prev62 / 86Next →