Total
29035 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-12254 | 1 Cisco | 1 Unified Intelligence Center | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting the malicious code. An exploit could allow the attacker to execute arbitrary code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve76848, CSCve76856. | |||||
CVE-2017-9336 | 1 Wp Editor.md Project | 1 Wp Editor.md | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post. | |||||
CVE-2018-5691 | 1 Sonicwall | 2 Analyzer, Global Management System | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module. | |||||
CVE-2017-9467 | 1 Paloaltonetworks | 1 Pan-os | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2017-1290 | 1 Ibm | 1 Openpages Grc Platform | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151. | |||||
CVE-2017-1291 | 1 Ibm | 2 Maximo Asset Management, Maximo Asset Management Essentials | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152. | |||||
CVE-2017-17937 | 1 Vanguard Project | 1 Marketplace Digital Products Php | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search. | |||||
CVE-2017-1000425 | 1 Liferay | 1 Liferay Portal | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter. | |||||
CVE-2018-5660 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_sub_title parameter. | |||||
CVE-2017-9451 | 1 Flatcore | 1 Flatcore | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs. | |||||
CVE-2017-17832 | 1 Serverscheck | 1 Monitoring Software | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page). | |||||
CVE-2017-10612 | 1 Juniper | 1 Junos Space | 2024-02-04 | 6.0 MEDIUM | 8.0 HIGH |
A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1. | |||||
CVE-2017-11320 | 1 Technicolor | 2 Tc7337, Tc7337 Firmware | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router. | |||||
CVE-2016-10706 | 1 Automattic | 1 Jetpack | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. | |||||
CVE-2017-16760 | 1 Inedo | 1 Buildmaster | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Inedo BuildMaster before 5.8.2 has XSS. | |||||
CVE-2017-17949 | 1 Cells | 1 Blog | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter. | |||||
CVE-2017-14594 | 1 Atlassian | 2 Jira, Jira Server | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter. | |||||
CVE-2017-1000488 | 2 Acquia, Mautic | 2 Mautic, Mautic | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form. | |||||
CVE-2016-6800 | 1 Apache | 1 Ofbiz | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01. | |||||
CVE-2017-15810 | 1 Popcash | 1 Popcash.net Code Integration Tool | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php. |