Total
29268 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-12111 | 1 Canon | 1 Efi Printme | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI. | |||||
CVE-2018-6936 | 2 D-link, Dlink | 2 Dir-600m C1 Firmware, Dir-600m C1 | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account. | |||||
CVE-2018-10068 | 1 Jdownloads | 1 Jdownloads | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The jDownloads extension before 3.2.59 for Joomla! has XSS. | |||||
CVE-2018-10567 | 1 Flexense | 1 Vx Search | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Flexense VX Search Enterprise from v10.1.12 to v10.7. | |||||
CVE-2018-11027 | 1 Ruckussecurity | 2 Icx7450-48, Icx7450-48 Firmware | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2018-0289 | 1 Cisco | 1 Identity Services Engine Software | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of requests stored in logs in the application management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted system. An exploit could allow the attacker to conduct cross-site scripting attacks when an administrator views the log files. Cisco Bug IDs: CSCvh11308. | |||||
CVE-2018-11485 | 1 Multidots | 1 Woocommerce Quick Reports | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order. | |||||
CVE-2018-10371 | 1 Wunderfarm | 1 Wf Cookie Consent | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title. | |||||
CVE-2017-1561 | 1 Ibm | 2 Rational Collaborative Lifecycle Management, Rational Quality Manager | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760. | |||||
CVE-2018-11690 | 1 Balbooa | 1 Gridbox | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. | |||||
CVE-2018-12654 | 1 Slims Akasia Project | 1 Slims Akasia | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI. | |||||
CVE-2018-7192 | 1 Osticket | 1 Osticket | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter. | |||||
CVE-2016-0223 | 1 Ibm | 1 Forms Server | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006. | |||||
CVE-2018-9130 | 1 Ibos | 1 Ibos | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
IBOS 4.4.3 has XSS via a company full name. | |||||
CVE-2018-8973 | 1 Otcms | 1 Otcms | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request. | |||||
CVE-2018-8152 | 1 Microsoft | 1 Exchange Server | 2024-02-04 | 5.8 MEDIUM | 5.4 MEDIUM |
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | |||||
CVE-2018-7717 | 1 Kubik-rubik | 1 Simple Image Gallery Extended | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1. | |||||
CVE-2018-0519 | 1 Fsi | 2 Fs010w, Fs010w Firmware | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-3717 | 1 Sencha | 1 Connect | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. | |||||
CVE-2018-12273 | 1 Ximdex | 1 Ximdex | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter. |