Vulnerabilities (CVE)

Filtered by CWE-79
Total 29256 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1202 1 Dell 1 Emc Isilon 2024-02-04 3.5 LOW 4.8 MEDIUM
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVE-2018-6354 1 Formspree 1 Formspree 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.
CVE-2018-12030 1 Chevereto 1 Chevereto 2024-02-04 3.5 LOW 5.4 MEDIUM
Chevereto Free before 1.0.13 has XSS.
CVE-2018-10023 1 Catfish-cms 1 Catfish Cms 2024-02-04 3.5 LOW 5.4 MEDIUM
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
CVE-2017-18217 1 Invoiceplane 1 Invoiceplane 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
CVE-2018-13039 1 Opendesa 1 Opensid 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI.
CVE-2018-2388 1 Sap 1 Internet Graphics Server 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2017-14190 1 Fortinet 1 Fortios 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.
CVE-2018-0582 1 Asus 2 Rt-ac68u, Rt-ac68u Firmware 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-1317 1 Ibm 2 Rational Collaborative Lifecycle Management, Rational Quality Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125729.
CVE-2018-1523 1 Ibm 1 Rational Quality Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141804.
CVE-2017-7840 1 Mozilla 1 Firefox 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add malicious tags to bookmarks, export them, and then open the resulting file. This vulnerability affects Firefox < 57.
CVE-2018-10366 1 User Project 1 User 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field.
CVE-2017-5827 1 Hp 1 Aruba Clearpass Policy Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
CVE-2018-0144 1 Cisco 1 Prime Data Center Network Manager 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvg81051.
CVE-2018-12973 1 Opentsdb 1 Opentsdb 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.
CVE-2018-12581 1 Phpmyadmin 1 Phpmyadmin 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.
CVE-2018-9997 1 Open-xchange 1 Open-xchange Appsuite 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.
CVE-2018-0603 1 Geminilabs 1 Site Reviews 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0559 1 Cybozu 1 Mailwise 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'Address' via unspecified vectors.