Total
29263 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-3763 | 1 Nextcloud | 1 Calendar | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins. | |||||
CVE-2017-16016 | 1 Punkave | 1 Sanitize-html | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability. | |||||
CVE-2018-9140 | 1 Samsung | 1 Samsung Mobile | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747. | |||||
CVE-2018-8732 | 1 Wampserver | 1 Wampserver | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter. | |||||
CVE-2018-5164 | 2 Canonical, Mozilla | 2 Ubuntu Linux, Firefox | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60. | |||||
CVE-2014-0014 | 1 Emberjs | 1 Ember.js | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload. | |||||
CVE-2018-4931 | 1 Adobe | 1 Experience Manager | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |||||
CVE-2018-2410 | 1 Sap | 1 Business One | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability. | |||||
CVE-2018-0565 | 1 Cybozu | 1 Office | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-12998 | 1 Zohocorp | 5 Firewall Analyzer, Manageengine Netflow Analyzer, Manageengine Network Configuration Manager and 2 more | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet. | |||||
CVE-2018-10566 | 1 Flexense | 1 Dupscout | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7. | |||||
CVE-2018-9985 | 1 Metinfo | 1 Metinfo | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator. | |||||
CVE-2018-5143 | 2 Canonical, Mozilla | 2 Ubuntu Linux, Firefox | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Firefox < 59. | |||||
CVE-2017-7534 | 1 Redhat | 1 Openshift | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod. | |||||
CVE-2018-1496 | 1 Ibm | 1 Content Navigator | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219. | |||||
CVE-2017-18175 | 1 Progress | 1 Sitefinity | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1. | |||||
CVE-2017-2743 | 1 Hp | 175 2a68a, 2a68a Firmware, 2a69a and 172 more | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be exploited to perform a cross site scripting (XSS) attack. | |||||
CVE-2018-0547 | 1 Soflyy | 1 Wp All Import | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-6858 | 1 Facebook Clone Script Project | 1 Facebook Clone Script | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script. | |||||
CVE-2018-1000020 | 1 Open-emr | 1 Openemr | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher. |