CVE-2020-11022
- EPSS 2.39%
- Veröffentlicht 29.04.2020 22:15:11
- Zuletzt bearbeitet 13.04.2026 15:16:29
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in...
CVE-2020-2936
- EPSS 0.32%
- Veröffentlicht 15.04.2020 14:15:36
- Zuletzt bearbeitet 21.11.2024 05:26:40
Vulnerability in the Oracle Financial Services Balance Sheet Planning product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileg...
CVE-2019-11358
- EPSS 2.36%
- Veröffentlicht 20.04.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:56
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the n...
CVE-2018-2626
- EPSS 0.65%
- Veröffentlicht 18.01.2018 02:29:20
- Zuletzt bearbeitet 21.11.2024 04:04:04
Vulnerability in the Oracle Financial Services Balance Sheet Planning component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthe...
CVE-2018-2592
- EPSS 0.97%
- Veröffentlicht 18.01.2018 02:29:18
- Zuletzt bearbeitet 21.11.2024 04:04:00
Vulnerability in the Oracle Financial Services Balance Sheet Planning component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low pri...