Search
Total
13741 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2017-8439 | 1 Elastic | 1 Kibana | 2020-08-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users. | |||||
| CVE-2016-10366 | 1 Elastic | 1 Kibana | 2020-08-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. | |||||
| CVE-2016-1000220 | 1 Elastic | 1 Kibana | 2020-08-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers. | |||||
| CVE-2020-7576 | 1 Siemens | 1 Opcenter Execution Core | 2020-08-14 | 3.5 LOW | 5.4 MEDIUM |
| A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2), Opcenter Execution Core (V8.2). An authenticated user with the ability to create containers, packages or register defects could perform stored Cross-Site Scripting (XSS) attacks within the vulnerable software. The impact of this attack could result in the session cookies of legitimate users being stolen. Should the attacker gain access to these cookies, they could then hijack the session and perform arbitrary actions in the name of the victim. | |||||
| CVE-2020-7303 | 1 Mcafee | 1 Data Loss Prevention | 2020-08-14 | 2.3 LOW | 4.1 MEDIUM |
| Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label. | |||||
| CVE-2020-13288 | 1 Gitlab | 1 Gitlab | 2020-08-14 | 3.5 LOW | 4.8 MEDIUM |
| In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page | |||||
| CVE-2020-2236 | 1 Jenkins | 1 Yet Another Build Visualizer | 2020-08-13 | 3.5 LOW | 5.4 MEDIUM |
| Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission. | |||||
| CVE-2020-13176 | 1 Teradici | 2 Cloud Access Connector, Cloud Access Connector Legacy | 2020-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16 and earlier for the Cloud Access Connector) contains a stored cross-site scripting (XSS) vulnerability which allows a remote unauthenticated attacker to poison log files with malicious JavaScript via the login page which is executed when an administrator views the logs within the application. | |||||
| CVE-2020-17362 | 1 Themeinprogress | 1 Nova Lite | 2020-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS. | |||||
| CVE-2020-17450 | 1 Php-fusion | 1 Php-fusion | 2020-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| PHP-Fusion 9.03 allows XSS on the preview page. | |||||
| CVE-2020-17449 | 1 Php-fusion | 1 Php-fusion | 2020-08-13 | 3.5 LOW | 5.4 MEDIUM |
| PHP-Fusion 9.03 allows XSS via the error_log file. | |||||
| CVE-2020-15597 | 1 Soplanning | 1 Soplanning | 2020-08-13 | 3.5 LOW | 5.4 MEDIUM |
| SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field. | |||||
| CVE-2020-15139 | 1 Mybb | 1 Mybb | 2020-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as a post or Private Message) and operates on a maliciously crafted MyCode message. This may occur on pages where message content is pre-filled using a GET/POST parameter, or on reply pages where a previously saved malicious message is quoted. After upgrading MyBB to 1.8.24, make sure to update the version attribute in the `codebuttons` template for non-default themes to serve the latest version of the patched `jscripts/bbcodes_sceditor.js` file. | |||||
| CVE-2020-17372 | 1 Sugarcrm | 1 Sugarcrm | 2020-08-13 | 3.5 LOW | 5.4 MEDIUM |
| SugarCRM before 10.1.0 (Q3 2020) allows XSS. | |||||
| CVE-2020-15071 | 1 Getsymphony | 1 Symphony | 2020-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading. | |||||
| CVE-2020-6300 | 1 Sap | 1 Businessobjects Business Intelligence Platform | 2020-08-13 | 3.5 LOW | 4.8 MEDIUM |
| SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not sufficiently encode user-controlled inputs for RecycleBin, resulting in Stored Cross-Site Scripting (XSS) vulnerability. | |||||
| CVE-2018-15913 | 1 Cloudera | 1 Cloudera Manager | 2020-08-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was not checked. As a result, the user could be automatically redirected to an attacker's external site or perform a malicious JavaScript function that results in cross-site scripting (XSS). This was fixed by not allowing any value in the returnUrl parameter with patterns such as http://, https://, //, or javascript. The only exceptions to this rule are the SAML Login/Logout URLs, which remain supported since they are explicitly configured and they are not passed via the returnUrl parameter. | |||||
| CVE-2020-10777 | 1 Redhat | 1 Cloudforms | 2020-08-12 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. | |||||
| CVE-2020-15907 | 1 Mahara | 1 Mahara | 2020-08-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript. | |||||
| CVE-2020-17480 | 1 Tiny | 1 Tinymce | 2020-08-11 | 4.3 MEDIUM | 6.1 MEDIUM |
| TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor. | |||||
| CVE-2020-16275 | 1 Carson-saint | 1 Saint Security Suite | 2020-08-11 | 4.3 MEDIUM | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | |||||
| CVE-2020-16278 | 1 Carson-saint | 1 Saint Security Suite | 2020-08-11 | 4.3 MEDIUM | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | |||||
| CVE-2020-15870 | 1 Sonatype | 1 Nexus Repository Manager 3 | 2020-08-11 | 4.3 MEDIUM | 6.1 MEDIUM |
| Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2). | |||||
| CVE-2020-15869 | 1 Sonatype | 1 Nexus Repository Manager 3 | 2020-08-11 | 4.3 MEDIUM | 5.4 MEDIUM |
| Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2). | |||||
| CVE-2020-17364 | 1 Usvn | 1 User-friendly Svn | 2020-08-11 | 4.3 MEDIUM | 6.1 MEDIUM |
| USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs. | |||||
| CVE-2020-16847 | 1 Extremenetworks | 1 Extreme Management Center | 2020-08-11 | 4.3 MEDIUM | 6.1 MEDIUM |
| Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887. | |||||
| CVE-2020-17476 | 1 Mibew | 1 Messenger | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| Mibew Messenger before 3.2.7 allows XSS via a crafted user name. | |||||
| CVE-2020-4541 | 1 Ibm | 1 Jazz Reporting Service | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039. | |||||
| CVE-2020-4533 | 1 Ibm | 1 Jazz Reporting Service | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717. | |||||
| CVE-2020-4539 | 1 Ibm | 1 Jazz Reporting Service | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
| CVE-2020-17451 | 1 Flatcore | 1 Flatcore | 2020-08-10 | 3.5 LOW | 4.8 MEDIUM |
| flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter. | |||||
| CVE-2020-15830 | 1 Jetbrains | 1 Teamcity | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI. | |||||
| CVE-2020-15831 | 1 Jetbrains | 1 Teamcity | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. | |||||
| CVE-2020-11110 | 1 Grafana | 1 Grafana | 2020-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
| Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. | |||||
| CVE-2020-15056 | 1 Tp-link | 2 Tl-ps310u, Tl-ps310u Firmware | 2020-08-09 | 2.3 LOW | 4.3 MEDIUM |
| TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name. | |||||
| CVE-2020-15060 | 1 Lindy-international | 2 42633, 42633 Firmware | 2020-08-09 | 2.3 LOW | 4.3 MEDIUM |
| Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name. | |||||
| CVE-2020-15064 | 1 Digitus | 2 Da-70254, Da-70254 Firmware | 2020-08-09 | 2.3 LOW | 4.3 MEDIUM |
| DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name. | |||||
| CVE-2014-1530 | 7 Canonical, Debian, Fedoraproject and 4 more | 16 Ubuntu Linux, Debian Linux, Fedora and 13 more | 2020-08-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation. | |||||
| CVE-2020-9036 | 1 Jeedom | 1 Jeedom | 2020-08-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| Jeedom through 4.0.38 allows XSS. | |||||
| CVE-2020-13819 | 1 Extremenetworks | 1 Extreme Management Center | 2020-08-06 | 4.3 MEDIUM | 6.1 MEDIUM |
| Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. | |||||
| CVE-2020-16192 | 1 Limesurvey | 1 Limesurvey | 2020-08-06 | 4.3 MEDIUM | 6.1 MEDIUM |
| LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters. | |||||
| CVE-2020-15944 | 1 Gantt-chart Project | 1 Gantt-chart | 2020-08-06 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated. | |||||
| CVE-2020-4525 | 1 Ibm | 2 Engineering Workflow Management, Rational Rhapsody Design Manager | 2020-08-06 | 3.5 LOW | 5.4 MEDIUM |
| IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182435. | |||||
| CVE-2020-10643 | 1 Osisoft | 1 Pi Vision | 2020-08-05 | 3.5 LOW | 5.4 MEDIUM |
| An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a known issue in a third-party component. | |||||
| CVE-2020-10614 | 1 Osisoft | 1 Pi Vision | 2020-08-05 | 3.5 LOW | 4.8 MEDIUM |
| In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display. | |||||
| CVE-2020-4396 | 1 Ibm | 1 Engineering Test Management | 2020-08-05 | 3.5 LOW | 5.4 MEDIUM |
| IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179359. | |||||
| CVE-2020-4542 | 1 Ibm | 1 Engineering Requirements Management Doors Next | 2020-08-05 | 3.5 LOW | 5.4 MEDIUM |
| IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 183046. | |||||
| CVE-2020-3460 | 1 Cisco | 1 Data Center Network Manager | 2020-08-05 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by intercepting a request from a user and injecting malicious data into an HTTP header. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. | |||||
| CVE-2020-11583 | 2 Microsoft, Plesk | 2 Windows, Obsidian | 2020-08-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | |||||
| CVE-2020-11584 | 2 Linux, Plesk | 2 Linux Kernel, Onyx | 2020-08-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | |||||
