Total
29035 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-10404 | 1 Liferay | 1 Liferay Portal | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted redirect field to modules/apps/foundation/frontend-js/frontend-js-spa-web/src/main/resources/META-INF/resources/init.jsp. | |||||
CVE-2018-5663 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php button_text_link parameter. | |||||
CVE-2017-12296 | 1 Cisco | 1 Webex Meetings Server | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf51241, CSCvf51261. | |||||
CVE-2017-12322 | 1 Cisco | 1 Email Encryption | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected service. An attacker could exploit these vulnerabilities by persuading a user to click a malicious link or by sending an HTTP request that could cause the affected service to redirect the request to a specified malicious URL. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web interface of the affected system or allow the attacker to access sensitive browser-based information on the affected system. These types of exploits could also be used in phishing attacks that send users to malicious websites without their knowledge. Cisco Bug IDs: CSCve77195, CSCve90978, CSCvf42310, CSCvf42703, CSCvf42723, CSCvf46169, CSCvf49999. | |||||
CVE-2017-1217 | 1 Ibm | 1 Websphere Portal | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857 | |||||
CVE-2017-14735 | 1 Antisamy Project | 1 Antisamy | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL. | |||||
CVE-2018-5076 | 1 Advanced Real Estate Script Project | 1 Advanced Real Estate Script | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter. | |||||
CVE-2017-15934 | 1 Artica | 1 Pandora Fms | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter. | |||||
CVE-2015-8349 | 1 Gameconnect | 1 Sourcebans | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php. | |||||
CVE-2017-18011 | 1 Clickbank | 1 Affiliate Ads For Clickbank Products | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter. | |||||
CVE-2017-14622 | 1 2kblater | 1 2kb Amazon Affiliates Store | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php. | |||||
CVE-2015-2046 | 1 Mantisbt | 1 Mantisbt | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20. | |||||
CVE-2017-14761 | 1 Genixcms | 1 Genixcms | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter. | |||||
CVE-2016-10366 | 1 Elastic | 1 Kibana | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. | |||||
CVE-2017-17929 | 1 Ordermanagementscript | 1 Professional Service Script | 2024-02-04 | 3.5 LOW | 4.8 MEDIUM |
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter. | |||||
CVE-2016-4906 | 1 Cybozu | 1 Garoon | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai. | |||||
CVE-2017-9802 | 1 Apache | 1 Sling Servlets Post | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings. | |||||
CVE-2017-6605 | 1 Cisco | 1 Identity Services Engine | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a reflective cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc85415. Known Affected Releases: 2.1(0.800). | |||||
CVE-2017-1178 | 1 Ibm | 1 Bigfix Security Compliance Analytics | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123430. | |||||
CVE-2017-17933 | 1 Netwin | 1 Surgeftp | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter. |