Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11348 1 Yunohost 1 Yunohost 2018-12-27 3.5 LOW 5.4 MEDIUM
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's session.
CVE-2018-19693 1 Tp5cms Project 1 Tp5cms 2018-12-27 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter.
CVE-2018-19785 1 Php-proxy 1 Php-proxy 2018-12-27 4.3 MEDIUM 6.1 MEDIUM
PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.
CVE-2018-19527 1 I4 1 Ai Si Assistant 2018-12-26 4.3 MEDIUM 6.1 MEDIUM
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
CVE-2018-0716 1 Qnap 1 Qts 2018-12-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.
CVE-2018-13323 1 Buffalo 2 Ts5600d1206, Ts5600d1206 Firmware 2018-12-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via the "username" cookie.
CVE-2018-19794 1 Internet2 1 Grouper 2018-12-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter.
CVE-2018-13022 1 Mi 2 Mi Router 3, Miwifi Os 2018-12-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a modified URL path.
CVE-2018-18642 1 Gitlab 1 Gitlab 2018-12-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.
CVE-2018-19892 1 Domainmod 1 Domainmod 2018-12-21 3.5 LOW 4.8 MEDIUM
DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.
CVE-2018-19749 1 Domainmod 1 Domainmod 2018-12-21 3.5 LOW 4.8 MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
CVE-2018-19751 1 Domainmod 1 Domainmod 2018-12-21 3.5 LOW 4.8 MEDIUM
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
CVE-2018-19752 1 Domainmod 1 Domainmod 2018-12-21 3.5 LOW 4.8 MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
CVE-2018-19913 1 Domainmod 1 Domainmod 2018-12-21 3.5 LOW 4.8 MEDIUM
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
CVE-2018-12310 1 Asustor 2 As602t, Data Master 2018-12-20 3.5 LOW 5.4 MEDIUM
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.
CVE-2018-12311 1 Asustor 2 As602t, Data Master 2018-12-20 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
CVE-2018-12305 1 Asustor 1 Data Master 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
CVE-2018-13360 1 Terra-master 1 Terramaster Operating System 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.
CVE-2018-14704 1 Drobo 2 5n2, 5n2 Firmware 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.
CVE-2018-13317 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
CVE-2018-13331 1 Terra-master 1 Terramaster Operating System 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing users by placing JavaScript in their usernames.
CVE-2018-14698 1 Drobo 2 5n2, 5n2 Firmware 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.
CVE-2018-14697 1 Drobo 2 5n2, 5n2 Firmware 2018-12-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.
CVE-2018-13357 1 Terra-master 1 Terramaster Operating System 2018-12-19 3.5 LOW 5.4 MEDIUM
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names.
CVE-2018-16096 1 Lenovo 8 System Management Module Firmware, Thinkagile Hx Enclosure 7x81, Thinkagile Hx Enclosure 7y87 and 5 more 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
CVE-2018-13351 1 Terra-master 1 Terramaster Operating System 2018-12-19 3.5 LOW 4.8 MEDIUM
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the edit password form.
CVE-2018-13349 1 Terra-master 1 Terramaster Operating System 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username.
CVE-2018-13335 1 Terra-master 1 Terramaster Operating System 2018-12-19 3.5 LOW 5.4 MEDIUM
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing shared folders via their descriptions.
CVE-2018-13333 1 Terra-master 1 Terramaster Operating System 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the permissions window by placing JavaScript in users' usernames.
CVE-2018-13329 1 Terra-master 1 Terramaster Operating System 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "lines" URL parameter.
CVE-2018-13334 1 Terra-master 1 Terramaster Operating System 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter.
CVE-2018-13312 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
CVE-2018-13308 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
CVE-2018-13309 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
CVE-2018-13310 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
CVE-2018-6076 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
CVE-2018-19469 1 Articlecms Project 1 Articlecms 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
CVE-2018-19547 1 Jtbc 1 Jtbc Php 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.
CVE-2018-19564 1 Goldplugins 1 Easy Testimonials 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
CVE-2018-19433 1 Showdoc 1 Showdoc 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
CVE-2018-19324 1 Kimsq 1 Rb 2018-12-17 3.5 LOW 5.4 MEDIUM
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI.
CVE-2018-16619 1 Sonatype 1 Nexus Repository Manager 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-19340 1 Guriddo 1 Form Php 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
CVE-2018-0695 1 Usvn 1 Usvn 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-19189 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
CVE-2018-19188 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
CVE-2018-19187 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
CVE-2018-19190 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
CVE-2018-19186 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
CVE-2018-8600 1 Microsoft 1 Azure App Service On Azure Stack 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.