Total
29271 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-10326 | 1 Printeron | 1 Printeron | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest. | |||||
CVE-2018-9328 | 1 Redbus Clone Script Project | 1 Redbus Clone Script | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php. | |||||
CVE-2018-2364 | 1 Sap | 2 Customer Relationship Management Webclient Ui, S4fnd | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability. | |||||
CVE-2018-8070 | 1 Qcms | 1 Qcms | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI. | |||||
CVE-2017-1293 | 1 Ibm | 2 Rational Collaborative Lifecycle Management, Rational Quality Manager | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125154. | |||||
CVE-2016-0303 | 1 Ibm | 1 Tivoli Integrated Portal | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2016-0261 | 1 Ibm | 2 Care Management, Curam Social Program Management | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604. | |||||
CVE-2018-12104 | 1 Airbnb | 1 Knowledge Repo | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI. | |||||
CVE-2017-15719 | 1 Wicket-jquery-ui Project | 1 Wicket-jquery-ui | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor. | |||||
CVE-2014-0883 | 1 Ibm | 1 Power Hardware Management Console | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Power Hardware Management Console (HMC) 7R7.1.0, 7R7.2.0, 7R7.3.0 through 7R7.3.5, 7R7.7.0 through SP3, and 7R7.8.0 before SP1 allows remote attackers to inject arbitrary web script or HTML via the user name on the logon screen. IBM X-Force ID: 91163. | |||||
CVE-2018-7303 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
The Calendar component in Tiki 17.1 allows HTML injection. | |||||
CVE-2018-8071 | 1 Mautic | 1 Mautic | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Mautic before v2.13.0 has stored XSS via a theme config file. | |||||
CVE-2018-5303 | 1 Impinj | 2 R420 Rfid Reader, R420 Rfid Reader Firmware | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the web application is vulnerable to Cross Site Scripting; this vulnerability allows an attacker to send malicious code to another user. | |||||
CVE-2018-4940 | 1 Adobe | 1 Coldfusion | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure. | |||||
CVE-2013-2999 | 1 Ibm | 1 Infosphere Data Replication Dashboard | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115. | |||||
CVE-2018-0276 | 1 Cisco | 1 Webex Connect Im | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvi07812. | |||||
CVE-2017-1567 | 1 Ibm | 1 Rational Doors | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769. | |||||
CVE-2018-0534 | 1 Arsenol Project | 1 Arsenol | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in ArsenoL Version 0.5 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2017-16356 | 1 Kubik-rubik | 1 Simple Image Gallery Extended | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter. | |||||
CVE-2017-18040 | 1 Atlassian | 1 Bamboo | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release. |