Vulnerabilities (CVE)

Filtered by CWE-79
Total 29035 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12254 1 Cisco 1 Unified Intelligence Center 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting the malicious code. An exploit could allow the attacker to execute arbitrary code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve76848, CSCve76856.
CVE-2017-9336 1 Wp Editor.md Project 1 Wp Editor.md 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.
CVE-2018-5691 1 Sonicwall 2 Analyzer, Global Management System 2024-02-04 3.5 LOW 5.4 MEDIUM
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.
CVE-2017-9467 1 Paloaltonetworks 1 Pan-os 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-1290 1 Ibm 1 Openpages Grc Platform 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151.
CVE-2017-1291 1 Ibm 2 Maximo Asset Management, Maximo Asset Management Essentials 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152.
CVE-2017-17937 1 Vanguard Project 1 Marketplace Digital Products Php 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
CVE-2017-1000425 1 Liferay 1 Liferay Portal 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
CVE-2018-5660 1 Responsive Coming Soon Page Project 1 Responsive Coming Soon Page 2024-02-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_sub_title parameter.
CVE-2017-9451 1 Flatcore 1 Flatcore 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
CVE-2017-17832 1 Serverscheck 1 Monitoring Software 2024-02-04 3.5 LOW 5.4 MEDIUM
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).
CVE-2017-10612 1 Juniper 1 Junos Space 2024-02-04 6.0 MEDIUM 8.0 HIGH
A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.
CVE-2017-11320 1 Technicolor 2 Tc7337, Tc7337 Firmware 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router.
CVE-2016-10706 1 Automattic 1 Jetpack 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
CVE-2017-16760 1 Inedo 1 Buildmaster 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Inedo BuildMaster before 5.8.2 has XSS.
CVE-2017-17949 1 Cells 1 Blog 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
CVE-2017-14594 1 Atlassian 2 Jira, Jira Server 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.
CVE-2017-1000488 2 Acquia, Mautic 2 Mautic, Mautic 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
CVE-2016-6800 1 Apache 1 Ofbiz 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01.
CVE-2017-15810 1 Popcash 1 Popcash.net Code Integration Tool 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.