Vulnerabilities (CVE)

Filtered by CWE-79
Total 29268 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-12111 1 Canon 1 Efi Printme 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.
CVE-2018-6936 2 D-link, Dlink 2 Dir-600m C1 Firmware, Dir-600m C1 2024-02-04 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
CVE-2018-10068 1 Jdownloads 1 Jdownloads 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The jDownloads extension before 3.2.59 for Joomla! has XSS.
CVE-2018-10567 1 Flexense 1 Vx Search 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Flexense VX Search Enterprise from v10.1.12 to v10.7.
CVE-2018-11027 1 Ruckussecurity 2 Icx7450-48, Icx7450-48 Firmware 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-0289 1 Cisco 1 Identity Services Engine Software 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of requests stored in logs in the application management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted system. An exploit could allow the attacker to conduct cross-site scripting attacks when an administrator views the log files. Cisco Bug IDs: CSCvh11308.
CVE-2018-11485 1 Multidots 1 Woocommerce Quick Reports 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
CVE-2018-10371 1 Wunderfarm 1 Wf Cookie Consent 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title.
CVE-2017-1561 1 Ibm 2 Rational Collaborative Lifecycle Management, Rational Quality Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760.
CVE-2018-11690 1 Balbooa 1 Gridbox 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2018-12654 1 Slims Akasia Project 1 Slims Akasia 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI.
CVE-2018-7192 1 Osticket 1 Osticket 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.
CVE-2016-0223 1 Ibm 1 Forms Server 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.
CVE-2018-9130 1 Ibos 1 Ibos 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
IBOS 4.4.3 has XSS via a company full name.
CVE-2018-8973 1 Otcms 1 Otcms 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
CVE-2018-8152 1 Microsoft 1 Exchange Server 2024-02-04 5.8 MEDIUM 5.4 MEDIUM
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
CVE-2018-7717 1 Kubik-rubik 1 Simple Image Gallery Extended 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
CVE-2018-0519 1 Fsi 2 Fs010w, Fs010w Firmware 2024-02-04 3.5 LOW 4.8 MEDIUM
Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-3717 1 Sencha 1 Connect 2024-02-04 3.5 LOW 5.4 MEDIUM
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
CVE-2018-12273 1 Ximdex 1 Ximdex 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.