Search
Total
20468 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-13758 | 1 Bitrix | 1 Bitrix24 | 2020-06-02 | 4.3 MEDIUM | 6.1 MEDIUM |
| modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload. | |||||
| CVE-2020-8035 | 1 Horde | 1 Groupware | 2020-06-01 | 4.3 MEDIUM | 6.1 MEDIUM |
| The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL. | |||||
| CVE-2020-8034 | 1 Horde | 2 Gollem, Groupware | 2020-05-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL. | |||||
| CVE-2018-18405 | 1 Jquery | 1 Jquery | 2020-05-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry. | |||||
| CVE-2017-1000427 | 1 Marked Project | 1 Marked | 2020-05-31 | 4.3 MEDIUM | 6.1 MEDIUM |
| marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser. | |||||
| CVE-2020-4306 | 1 Ibm | 1 Planning Analytics Local | 2020-05-29 | 3.5 LOW | 5.4 MEDIUM |
| IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176735. | |||||
| CVE-2020-4419 | 1 Ibm | 1 Jazz Reporting Service | 2020-05-29 | 3.5 LOW | 5.4 MEDIUM |
| IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071. | |||||
| CVE-2020-13660 | 1 Cmsmadesimple | 1 Cms Made Simple | 2020-05-29 | 3.5 LOW | 4.8 MEDIUM |
| CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name. | |||||
| CVE-2020-13644 | 1 Pickplugins | 1 Accordion | 2020-05-28 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion. | |||||
| CVE-2020-8170 | 1 Ui | 51 Ag-hp-2g16, Ag-hp-2g20, Ag-hp-5g23 and 48 more | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Multiple end-points with parameters vulnerable to reflected cross site scripting (XSS), allowing attackers to abuse the user' session information and/or account takeover of the admin user.Mitigation:Update to the latest AirMax AirOS firmware version available at the AirMax download page. | |||||
| CVE-2017-8876 | 1 Getsymphony | 1 Symphony | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php. | |||||
| CVE-2020-13487 | 1 Bbpress | 1 Bbpress | 2020-05-28 | 3.5 LOW | 4.8 MEDIUM |
| The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI. | |||||
| CVE-2015-1864 | 1 Kallithea-scm | 1 Kallithea | 2020-05-28 | 3.5 LOW | 5.4 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description. | |||||
| CVE-2020-13628 | 1 Centreon | 3 Centreon Host-monitoring Widget, Centreon Service-monitoring Widget, Centreon Tactical-overview Widget | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget. | |||||
| CVE-2020-10946 | 1 Centreon | 3 Centreon Host-monitoring Widget, Centreon Service-monitoring Widget, Centreon Tactical-overview Widget | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget. | |||||
| CVE-2020-13627 | 1 Centreon | 3 Centreon Host-monitoring Widget, Centreon Service-monitoring Widget, Centreon Tactical-overview Widget | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget. | |||||
| CVE-2020-12261 | 1 Opmantek | 1 Open-audit | 2020-05-28 | 3.5 LOW | 5.4 MEDIUM |
| Open-AudIT 3.3.0 allows an XSS attack after login. | |||||
| CVE-2020-8603 | 1 Trendmicro | 1 Interscan Web Security Virtual Appliance | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | |||||
| CVE-2020-13430 | 1 Grafana | 1 Grafana | 2020-05-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | |||||
| CVE-2020-13633 | 1 Fork-cms | 1 Fork Cms | 2020-05-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Fork before 5.8.3 allows XSS via navigation_title or title. | |||||
| CVE-2020-4358 | 1 Ibm | 1 Spectrum Scale | 2020-05-27 | 3.5 LOW | 5.4 MEDIUM |
| IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178762. | |||||
| CVE-2020-1063 | 1 Microsoft | 1 Dynamics 365 | 2020-05-27 | 3.5 LOW | 5.4 MEDIUM |
| A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | |||||
| CVE-2020-13459 | 1 Verbb | 1 Image Resizer | 2020-05-27 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action. | |||||
| CVE-2020-1055 | 1 Microsoft | 3 Windows 10, Windows Server 2016, Windows Server 2019 | 2020-05-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'. | |||||
| CVE-2020-1105 | 1 Microsoft | 2 Sharepoint Enterprise Server, Sharepoint Server | 2020-05-26 | 3.5 LOW | 5.4 MEDIUM |
| A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1104, CVE-2020-1107. | |||||
| CVE-2020-1104 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2020-05-26 | 3.5 LOW | 5.4 MEDIUM |
| A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1105, CVE-2020-1107. | |||||
| CVE-2020-1107 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2020-05-26 | 3.5 LOW | 5.4 MEDIUM |
| A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1104, CVE-2020-1105. | |||||
| CVE-2020-8789 | 1 Composr Project | 1 Composr | 2020-05-26 | 3.5 LOW | 5.4 MEDIUM |
| Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration. | |||||
| CVE-2020-13429 | 1 Grafana | 1 Piechart-panel | 2020-05-26 | 3.5 LOW | 5.4 MEDIUM |
| legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option. | |||||
| CVE-2020-11888 | 1 Python-markdown2 Project | 1 Python-markdown2 | 2020-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute. | |||||
| CVE-2011-2342 | 1 Google | 1 Chrome | 2020-05-22 | 4.3 MEDIUM | N/A |
| The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | |||||
| CVE-2011-1819 | 1 Google | 1 Chrome | 2020-05-22 | 4.3 MEDIUM | N/A |
| Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions. | |||||
| CVE-2020-1099 | 1 Microsoft | 2 Sharepoint Enterprise Server, Sharepoint Server | 2020-05-22 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106. | |||||
| CVE-2020-1100 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2020-05-22 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106. | |||||
| CVE-2011-1815 | 1 Google | 1 Chrome | 2020-05-22 | 4.3 MEDIUM | N/A |
| Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions. | |||||
| CVE-2020-1101 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2020-05-22 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1106. | |||||
| CVE-2020-13258 | 1 Contentful | 1 Python Example | 2020-05-21 | 4.3 MEDIUM | 6.1 MEDIUM |
| Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py. | |||||
| CVE-2020-13145 | 1 Edx | 1 Open Edx Platform | 2020-05-20 | 3.5 LOW | 5.4 MEDIUM |
| Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. | |||||
| CVE-2020-13239 | 1 Dolibarr | 1 Dolibarr | 2020-05-20 | 3.5 LOW | 5.4 MEDIUM |
| The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS. | |||||
| CVE-2020-13225 | 1 Phpipam | 1 Phpipam | 2020-05-20 | 3.5 LOW | 4.8 MEDIUM |
| phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget. | |||||
| CVE-2020-11845 | 1 Microfocus | 1 Service Manager | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML. | |||||
| CVE-2020-6956 | 1 Pcs | 1 Dexicon Enterprise | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp. | |||||
| CVE-2020-4298 | 1 Ibm | 2 Infosphere Information Server, Infosphere Information Server On Cloud | 2020-05-19 | 3.5 LOW | 5.4 MEDIUM |
| IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475. | |||||
| CVE-2019-20802 | 1 Readdle | 1 Documents | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a crafted directory name on a victim's device. However, a crafted directory name can occur if a victim extracts a ZIP archive that was provided by an attacker. | |||||
| CVE-2020-13153 | 1 Misp | 1 Misp | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. | |||||
| CVE-2020-12882 | 1 Rcos | 1 Submitty | 2020-05-19 | 3.5 LOW | 5.4 MEDIUM |
| Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow. | |||||
| CVE-2020-7809 | 1 Altools | 1 Alsong | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by improper validation of user input. A remote attacker could exploit this vulnerability by tricking the victim to open ALSong Album(sab) file. | |||||
| CVE-2019-15083 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page. | |||||
| CVE-2020-13094 | 1 Dolibarr | 1 Dolibarr | 2020-05-19 | 3.5 LOW | 5.4 MEDIUM |
| Dolibarr before 11.0.4 allows XSS. | |||||
| CVE-2020-11930 | 1 Gtranslate | 1 Translate Wordpress With Gtranslate | 2020-05-19 | 4.3 MEDIUM | 6.1 MEDIUM |
| The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option. | |||||
