Vulnerabilities > Parallels

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2019-18793 Cross-site Scripting vulnerability in Parallels Plesk Panel 9.5
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
network
low complexity
parallels CWE-79
6.1
2018-02-28 CVE-2017-9447 Path Traversal vulnerability in Parallels Remote Application Server 15.5
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory.
network
low complexity
parallels CWE-22
7.5