Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2022-48345
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
Braintree\/sanitize Url
6.0.2+
CRITICAL 9.8
CVE-2022-21129
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'…
Nemo Appium
0.0.9+
MEDIUM 6.1
CVE-2017-6217
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
Adaptive Payments Sdk
No fix yet
MEDIUM 5.4
CVE-2017-6213
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
Php Invoice Sdk
after 3.9.0
MEDIUM 5.4
CVE-2017-6215
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
Php Permissions Sdk
after 3.9.1
HIGH 8.1
CVE-2013-7202
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
Paypal
after 5.3
HIGH 7.4
CVE-2013-7201
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain s…
Paypal
after 5.3
MEDIUM 6.1
CVE-2017-6099
Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers t…
Merchant Sdk Php
No fix yet
MEDIUM 5.8
CVE-2011-5237
PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.…
Wps Toolkit
Mitigation only
MEDIUM 5.8
CVE-2012-5802
The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…
Paypal
No fix yet
MEDIUM 5.8
CVE-2012-5805
The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…
Instant Payment Notification
No fix yet
MEDIUM 5.8
CVE-2012-5806
The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjec…
Payments Pro
No fix yet
MEDIUM 5.8
CVE-2012-5787
The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…
Merchant Sdk
Patch available
MEDIUM 5.8
CVE-2012-5788
The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…
Ipn
No fix yet
MEDIUM 5.8
CVE-2012-5789
PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)…
Payments Standard
No fix yet
MEDIUM 5.8
CVE-2012-5790
PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub…
Payments Standard
No fix yet
MEDIUM 5.8
CVE-2012-5791
PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50…
Invoicing
No fix yet
MEDIUM 5.0
CVE-2012-2058
The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.
Ubercart Payflow
Mitigation only
MEDIUM 5.0
CVE-2006-0201
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter fals…
Php Toolkit
after 0.50