Search
Total
13741 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-10571 | 1 Open-emr | 1 Openemr | 2018-06-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/finder/finder_navigation.php; (2) key parameter to interface/billing/get_claim_file.php; (3) formid or (4) formseq parameter to interface/orders/types.php; (5) eraname, (6) paydate, (7) post_to_date, (8) deposit_date, (9) debug, or (10) InsId parameter to interface/billing/sl_eob_process.php; (11) form_source, (12) form_paydate, (13) form_deposit_date, (14) form_amount, (15) form_name, (16) form_pid, (17) form_encounter, (18) form_date, or (19) form_to_date parameter to interface/billing/sl_eob_search.php; (20) codetype or (21) search_term parameter to interface/de_identification_forms/find_code_popup.php; (22) search_term parameter to interface/de_identification_forms/find_drug_popup.php; (23) search_term parameter to interface/de_identification_forms/find_immunization_popup.php; (24) id parameter to interface/forms/CAMOS/view.php; (25) id parameter to interface/forms/reviewofs/view.php; or (26) list_id parameter to library/custom_template/personalize.php. | |||||
| CVE-2018-8900 | 1 Gemalto | 1 Sentinel Ldk Rte | 2018-06-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability. | |||||
| CVE-2018-0578 | 1 Pixelyoursite | 1 Pixelyoursite | 2018-06-13 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting vulnerability in PixelYourSite plugin prior to version 5.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2018-6362 | 1 Ehcp | 1 Easy Hosting Control Panel | 2018-06-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie. | |||||
| CVE-2018-6361 | 1 Ehcp | 1 Easy Hosting Control Panel | 2018-06-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account. | |||||
| CVE-2018-10817 | 1 Severalnines | 1 Clustercontrol | 2018-06-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Severalnines ClusterControl before 1.6.0-4699 allows XSS. | |||||
| CVE-2018-1000177 | 1 Jenkins | 1 S3 Publisher | 2018-06-13 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control file names of uploaded files to define file names containing JavaScript that would be executed in another user's browser when that user performs some UI actions. | |||||
| CVE-2017-8896 | 1 Owncloud | 1 Owncloud | 2018-06-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters. | |||||
| CVE-2018-10371 | 1 Wunderfarm | 1 Wf Cookie Consent | 2018-06-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title. | |||||
| CVE-2018-5303 | 1 Impinj | 2 R420 Rfid Reader, R420 Rfid Reader Firmware | 2018-06-13 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the web application is vulnerable to Cross Site Scripting; this vulnerability allows an attacker to send malicious code to another user. | |||||
| CVE-2018-9111 | 1 Foxconn | 2 Ap-fc4064-t, Ap-fc4064-t Firmware | 2018-06-13 | 3.5 LOW | 5.4 MEDIUM |
| Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configuration of a user account. An attacker can execute arbitrary script on an unsuspecting user's browser. | |||||
| CVE-2018-10314 | 1 Opmantek | 1 Open-audit | 2018-06-13 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section. | |||||
| CVE-2018-10310 | 1 Catapultthemes | 1 Cookie Consent | 2018-06-13 | 3.5 LOW | 5.4 MEDIUM |
| A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser. | |||||
| CVE-2018-10686 | 1 Vestacp | 1 Control Panel | 2018-06-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php. | |||||
| CVE-2018-10164 | 1 Tp-link | 1 Eap Controller | 2018-06-12 | 3.5 LOW | 5.4 MEDIUM |
| Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows. | |||||
| CVE-2018-10165 | 1 Tp-link | 1 Eap Controller | 2018-06-12 | 3.5 LOW | 5.4 MEDIUM |
| Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows. | |||||
| CVE-2018-1000172 | 1 Imagely | 1 Nextgen Gallery | 2018-06-07 | 3.5 LOW | 4.8 MEDIUM |
| Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45. | |||||
| CVE-2018-10570 | 1 Frogcms Project | 1 Frogcms | 2018-06-07 | 3.5 LOW | 4.8 MEDIUM |
| Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field. | |||||
| CVE-2018-10665 | 1 Ilias | 1 Ilias | 2018-06-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files. | |||||
| CVE-2018-1502 | 1 Ibm | 1 Content Manager | 2018-06-06 | 3.5 LOW | 5.4 MEDIUM |
| IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141338. | |||||
| CVE-2018-1430 | 1 Ibm | 1 Api Connect | 2018-06-06 | 3.5 LOW | 5.4 MEDIUM |
| IBM API Connect 5.0.0.0 through 5.0.8.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139226. | |||||
| CVE-2018-0711 | 1 Qnap | 1 Qts | 2018-06-06 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML. | |||||
| CVE-2018-10095 | 1 Dolibarr | 1 Dolibarr | 2018-06-06 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php. | |||||
| CVE-2018-5228 | 1 Atlassian | 2 Crucible, Fisheye | 2018-06-06 | 4.3 MEDIUM | 6.1 MEDIUM |
| The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers. | |||||
| CVE-2018-10430 | 1 Dilicms | 1 Dilicms | 2018-06-06 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php. | |||||
| CVE-2018-7465 | 1 Virtuemart | 1 Virtuemart | 2018-06-06 | 3.5 LOW | 5.4 MEDIUM |
| An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything after the </textarea>, leading to a possible XSS. | |||||
| CVE-2018-10309 | 1 Responsive Cookie Consent Project | 1 Responsive Cookie Consent | 2018-06-06 | 3.5 LOW | 5.4 MEDIUM |
| The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. | |||||
| CVE-2018-10527 | 1 Easycms Project | 1 Easycms | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI. | |||||
| CVE-2018-8149 | 1 Microsoft | 1 Sharepoint Server | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8156, CVE-2018-8168. | |||||
| CVE-2018-8155 | 1 Microsoft | 2 Sharepoint Foundation, Sharepoint Server | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168. | |||||
| CVE-2018-8156 | 1 Microsoft | 2 Project Server, Sharepoint Server | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8168. | |||||
| CVE-2018-8168 | 1 Microsoft | 1 Sharepoint Server | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8156. | |||||
| CVE-2018-10259 | 1 Hrsale Project | 1 Hrsale | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | |||||
| CVE-2018-10726 | 1 Datenstrom | 1 Yellow | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| ** DISPUTED ** A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS. | |||||
| CVE-2018-10365 | 1 Threads To Link Project | 1 Threads To Link | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized. | |||||
| CVE-2018-10364 | 1 Bigtreecms | 1 Bigtree Cms | 2018-06-05 | 3.5 LOW | 5.4 MEDIUM |
| BigTree before 4.2.22 has XSS in the Users management page via the name or company field. | |||||
| CVE-2018-10568 | 1 Flexense | 1 Disksorter | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS exists in Flexense DiskSorter Enterprise from v9.5.12 to v10.7. | |||||
| CVE-2018-10294 | 1 Flexense | 1 Diskboss | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS. | |||||
| CVE-2018-10565 | 1 Flexense | 1 Disksavvy | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS exists in Flexense DiskSavvy Enterprise from v10.4 to v10.7. | |||||
| CVE-2018-10566 | 1 Flexense | 1 Dupscout | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7. | |||||
| CVE-2018-10567 | 1 Flexense | 1 Vx Search | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS exists in Flexense VX Search Enterprise from v10.1.12 to v10.7. | |||||
| CVE-2018-10564 | 1 Flexense | 1 Diskpulse | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS exists in Flexense DiskPulse Enterprise from v10.4 to v10.7. | |||||
| CVE-2018-10563 | 1 Flexense | 1 Syncbreeze | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| An XSS in Flexense SyncBreeze affects all versions (tested from SyncBreeze Enterprise from v10.1 to v10.7). | |||||
| CVE-2018-1473 | 1 Ibm | 1 Bigfix Platform | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691. | |||||
| CVE-2018-1363 | 1 Ibm | 1 Jazz Reporting Service | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
| IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448. | |||||
| CVE-2017-1750 | 1 Ibm | 1 Jazz Reporting Service | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
| IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523. | |||||
| CVE-2017-13073 | 1 Qnap | 1 Photo Station | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML. | |||||
| CVE-2018-10268 | 1 Fastadmin | 1 Fastadmin | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter. | |||||
| CVE-2018-6518 | 1 Compo | 1 Composr Cms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
| Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php. | |||||
| CVE-2018-10329 | 1 Phpipam | 1 Phpipam | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. | |||||
