Total
29081 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-12590 | 1 Asus | 2 Rt-n14uhp, Rt-n14uhp Firmware | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter. | |||||
CVE-2015-2324 | 1 10web | 1 Photo Gallery | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-8728 | 1 Kontena | 1 Kontena | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI. | |||||
CVE-2018-1384 | 1 Ibm | 4 Business Process Manager, Business Process Manager Enterprise Service Bus, Websphere Enterprise Service Bus and 1 more | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135. | |||||
CVE-2017-9783 | 1 Projectsend | 1 Projectsend | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated. | |||||
CVE-2018-9122 | 1 Crea8social | 1 Crea8social | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI. | |||||
CVE-2018-3735 | 1 Bracket-template Project | 1 Bracket-template | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template | |||||
CVE-2018-0908 | 1 Microsoft | 1 Identity Manager | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability." | |||||
CVE-2018-11627 | 2 Redhat, Sinatrarb | 2 Cloudforms, Sinatra | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. | |||||
CVE-2018-6940 | 1 Nat32 | 1 Nat32 | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF. | |||||
CVE-2018-1186 | 1 Dell | 1 Emc Isilon | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website. | |||||
CVE-2017-8783 | 1 Synacor | 1 Zimbra Collaboration Suite | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS. | |||||
CVE-2018-0557 | 1 Cybozu | 1 Mailwise | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified vectors. | |||||
CVE-2018-1000084 | 1 Wolfcms | 1 Wolf Cms | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout Name . | |||||
CVE-2018-6182 | 1 Mahara | 1 Mahara | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server. | |||||
CVE-2018-10026 | 1 Yzmcms | 1 Yzmcms | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php. | |||||
CVE-2018-8247 | 1 Microsoft | 2 Office Online Server, Office Web Apps | 2024-02-04 | 5.8 MEDIUM | 5.4 MEDIUM |
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Office Online Server. This CVE ID is unique from CVE-2018-8245. | |||||
CVE-2015-3618 | 1 Nagios | 1 Business Process Intelligence | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php. | |||||
CVE-2018-8906 | 1 Dsmall Project | 1 Dsmall | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html. | |||||
CVE-2018-11366 | 1 Loginizer | 1 Loginizer | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0. |