Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Braintree\/sanitize Url MEDIUM 6.1
CVE-2022-48345

sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

Fix: 6.0.2+
Fix from $1,600 2023-02-24
Nemo Appium CRITICAL 9.8
CVE-2022-21129

Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup'…

Fix: 0.0.9+
Fix from $2,300 2023-01-31
Adaptive Payments Sdk MEDIUM 6.1
CVE-2017-6217

paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution

No fix yet
Fix from $1,600 2019-07-10
Php Invoice Sdk MEDIUM 5.4
CVE-2017-6213

paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.

Fix: after 3.9.0
Fix from $1,600 2018-08-02
Php Permissions Sdk MEDIUM 5.4
CVE-2017-6215

paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.

Fix: after 3.9.1
Fix from $1,600 2018-08-02
Paypal HIGH 8.1
CVE-2013-7202

The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.

Fix: after 5.3
Fix from $1,950 2018-04-27
Paypal HIGH 7.4
CVE-2013-7201

WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain s…

Fix: after 5.3
Fix from $1,950 2018-04-27
Merchant Sdk Php MEDIUM 6.1
CVE-2017-6099

Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers t…

No fix yet
Fix from $1,600 2017-02-24
Wps Toolkit MEDIUM 5.8
CVE-2011-5237

PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.…

Mitigation only
Fix from $1,600 2012-11-06
Paypal MEDIUM 5.8
CVE-2012-5802

The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…

No fix yet
Fix from $1,600 2012-11-04
Instant Payment Notification MEDIUM 5.8
CVE-2012-5805

The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…

No fix yet
Fix from $1,600 2012-11-04
Payments Pro MEDIUM 5.8
CVE-2012-5806

The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjec…

No fix yet
Fix from $1,600 2012-11-04
Merchant Sdk MEDIUM 5.8
CVE-2012-5787

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

Patch available
Fix from $1,600 2012-11-04
Ipn MEDIUM 5.8
CVE-2012-5788

The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

No fix yet
Fix from $1,600 2012-11-04
Payments Standard MEDIUM 5.8
CVE-2012-5789

PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)…

No fix yet
Fix from $1,600 2012-11-04
Payments Standard MEDIUM 5.8
CVE-2012-5790

PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub…

No fix yet
Fix from $1,600 2012-11-04
Invoicing MEDIUM 5.8
CVE-2012-5791

PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50…

No fix yet
Fix from $1,600 2012-11-04
Ubercart Payflow MEDIUM 5.0
CVE-2012-2058

The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

Mitigation only
Fix from $1,600 2012-09-17
Php Toolkit MEDIUM 5.0
CVE-2006-0201

Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter fals…

Fix: after 0.50
Fix from $1,600 2006-01-13