Search
Total
20468 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-10779 | 1 Gchq | 1 Stroom | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom UI via an XSS vulnerability to take full control of the Stroom UI on behalf of the logged-in user. | |||||
| CVE-2020-1933 | 2 Apache, Mozilla | 2 Nifi, Firefox | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers. | |||||
| CVE-2019-15607 | 1 Nodered | 1 Node-red | 2020-01-29 | 3.5 LOW | 5.4 MEDIUM |
| A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc. | |||||
| CVE-2012-5384 | 1 Webcalendar Project | 1 Webcalendar | 2020-01-29 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5) $ext_users[] variables in view_entry.php, different vectors than CVE-2012-0846. | |||||
| CVE-2013-1421 | 1 Webcalendar Project | 1 Webcalendar | 2020-01-29 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php. | |||||
| CVE-2019-16024 | 1 Cisco | 2 Crosswork Change Automation, Crosswork Network Automation | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the web-based management interface of Cisco Crosswork Change Automation could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
| CVE-2019-16008 | 1 Cisco | 38 Ip Phone 6821, Ip Phone 6821 Firmware, Ip Phone 6825 and 35 more | 2020-01-29 | 3.5 LOW | 5.4 MEDIUM |
| A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based GUI of an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
| CVE-2019-15313 | 1 Zimbra | 1 Collaboration Server | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability. | |||||
| CVE-2020-5223 | 1 Privatebin | 1 Privatebin | 2020-01-29 | 2.1 LOW | 4.4 MEDIUM |
| In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain conditions, a user provided attachment file name can inject HTML leading to a persistent Cross-site scripting (XSS) vulnerability. The vulnerability has been fixed in PrivateBin v1.3.2 & v1.2.2. Admins are urged to upgrade to these versions to protect the affected users. | |||||
| CVE-2020-7997 | 1 Asus | 2 Rt-ac66u, Rt-ac66u Firmware | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature. | |||||
| CVE-2019-10770 | 1 Ratpack | 1 Ratpack | 2020-01-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode. | |||||
| CVE-2013-0286 | 1 Pinboard Project | 1 Pinboard | 2020-01-29 | 3.5 LOW | 5.4 MEDIUM |
| Pinboard 1.0.6 theme for Wordpress has XSS. | |||||
| CVE-2019-15586 | 1 Gitlab | 1 Gitlab | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. | |||||
| CVE-2019-12427 | 1 Zimbra | 1 Collaboration Server | 2020-01-28 | 3.5 LOW | 4.8 MEDIUM |
| Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console. | |||||
| CVE-2019-8947 | 1 Zimbra | 1 Collaboration Server | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS. | |||||
| CVE-2019-8946 | 1 Zimbra | 1 Collaboration Server | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. | |||||
| CVE-2019-8945 | 1 Zimbra | 1 Collaboration Server | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. | |||||
| CVE-2019-11318 | 1 Synacor | 1 Zimbra Collaboration Server | 2020-01-28 | 3.5 LOW | 5.4 MEDIUM |
| Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS. | |||||
| CVE-2015-2249 | 1 Synacor | 1 Zimbra Collaboration Server | 2020-01-28 | 3.5 LOW | 5.4 MEDIUM |
| Zimbra Collaboration before 8.6.0 patch5 has XSS. | |||||
| CVE-2014-5500 | 1 Synacor | 1 Zimbra Collaboration Server | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Synacor Zimbra Collaboration before 8.0.8 has XSS. | |||||
| CVE-2019-6036 | 1 F-revocrm | 1 F-revocrm | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2019-16015 | 1 Cisco | 1 Data Center Analytics Framework | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information on the affected system. | |||||
| CVE-2019-19592 | 1 Jamasoftware | 1 Connect | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Jama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting | |||||
| CVE-2020-3129 | 1 Cisco | 1 Unity Connection | 2020-01-28 | 3.5 LOW | 4.8 MEDIUM |
| A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing crafted data to a specific field within the interface. A successful exploit could allow the attacker to store an XSS attack within the interface. This stored XSS attack would then be executed on the system of any user viewing the attacker-supplied data element. | |||||
| CVE-2020-3136 | 1 Cisco | 1 Jabber Guest | 2020-01-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information. This vulnerability affects Cisco Jabber Guest releases 11.1(2) and earlier. | |||||
| CVE-2020-7989 | 1 Adive | 1 Framework | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Adive Framework 2.0.8 has admin/user/add userUsername XSS. | |||||
| CVE-2020-7990 | 1 Adive | 1 Framework | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Adive Framework 2.0.8 has admin/user/add userName XSS. | |||||
| CVE-2020-7249 | 1 Smc | 2 D3g0804, D3g0804 Firmware | 2020-01-27 | 3.5 LOW | 4.8 MEDIUM |
| SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the admin account). | |||||
| CVE-2020-7996 | 1 Dolibarr | 1 Dolibarr | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header. | |||||
| CVE-2020-6843 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2020-01-27 | 3.5 LOW | 4.8 MEDIUM |
| Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959. | |||||
| CVE-2019-15278 | 1 Cisco | 2 Finesse, Unified Contact Center Express | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information. | |||||
| CVE-2019-3686 | 1 Suse | 1 Openqa | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through the bug bounty program of Offensive Security | |||||
| CVE-2019-20003 | 1 Dicube | 1 Easescreen Crystal | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication. | |||||
| CVE-2019-11997 | 1 Hp | 1 Enhanced Internet Usage Manager | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the vulnerability in eIUM. The eIUM 8.3 FP01 customers are advised to install eIUM83FP01Patch_QXCR1001711284.20190806-1244 patch. The eIUM 9.0 customers are advised to upgrade to eIUM 9.0 FP02 PI5 or later versions. For other versions, please, contact the product support. | |||||
| CVE-2012-6344 | 1 Novell | 1 Zenworks Configuration Management | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Novell ZENworks Configuration Management before 11.2.4 allows XSS. | |||||
| CVE-2015-6748 | 1 Jsoup | 1 Jsoup | 2020-01-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. | |||||
| CVE-2020-7937 | 1 Plone | 1 Plone | 2020-01-24 | 3.5 LOW | 5.4 MEDIUM |
| An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site. | |||||
| CVE-2020-7104 | 1 Kibokolabs | 1 Chained Quiz | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter. | |||||
| CVE-2020-7239 | 1 Ibm | 1 Chatbot With Ibm Watson | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScript is sent. | |||||
| CVE-2020-7228 | 1 Codepeople | 1 Calculated Fields Form | 2020-01-24 | 3.5 LOW | 5.4 MEDIUM |
| The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user. | |||||
| CVE-2019-16512 | 1 Connectwise | 1 Control | 2020-01-24 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance modifier. | |||||
| CVE-2020-7470 | 1 Sonoff | 4 Th10, Th10 Firmware, Th16 and 1 more | 2020-01-24 | 3.5 LOW | 4.8 MEDIUM |
| Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password). | |||||
| CVE-2018-17981 | 1 Lifesize | 4 Express 220, Express 220 Firmware, Room 220i and 1 more | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter. | |||||
| CVE-2011-3622 | 1 Phorum | 1 Phorum | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18. | |||||
| CVE-2016-1000237 | 1 Apostrophecms | 1 Sanitize-html | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| sanitize-html before 1.4.3 has XSS. | |||||
| CVE-2014-7238 | 1 Formget | 1 Contact Form Integrated With Google Maps | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS | |||||
| CVE-2020-1607 | 1 Juniper | 44 Ex2300, Ex2300-c, Ex3400 and 41 more | 2020-01-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S15; 12.3X48 versions prior to 12.3X48-D86, 12.3X48-D90 on SRX Series; 14.1X53 versions prior to 14.1X53-D51 on EX and QFX Series; 15.1F6 versions prior to 15.1F6-S13; 15.1 versions prior to 15.1R7-S5; 15.1X49 versions prior to 15.1X49-D181, 15.1X49-D190 on SRX Series; 15.1X53 versions prior to 15.1X53-D238 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D592 on EX2300/EX3400 Series; 16.1 versions prior to 16.1R4-S13, 16.1R7-S5; 16.2 versions prior to 16.2R2-S10; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R1-S9, 17.2R3-S2; 17.3 versions prior to 17.3R2-S5, 17.3R3-S5; 17.4 versions prior to 17.4R2-S6, 17.4R3; 18.1 versions prior to 18.1R3-S7; 18.2 versions prior to 18.2R2-S5, 18.2R3; 18.3 versions prior to 18.3R1-S6, 18.3R2-S1, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2; 19.1 versions prior to 19.1R1-S2, 19.1R2. | |||||
| CVE-2011-3595 | 1 Joomla | 1 Joomla\! | 2020-01-24 | 3.5 LOW | 5.4 MEDIUM |
| Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. | |||||
| CVE-2020-7915 | 1 Eaton | 2 5p 850, 5p 850 Firmware | 2020-01-24 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator. | |||||
| CVE-2019-17634 | 1 Eclipse | 1 Memory Analyzer | 2020-01-24 | 8.5 HIGH | 9.0 CRITICAL |
| Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to occur. The heap dump could be specially crafted, or could come from a crafted application or from an application processing malicious data. The vulnerability is present whena report is generated and opened from the Memory Analyzer graphical user interface, or when a report generated in batch mode is then opened in Memory Analyzer or by a web browser. The vulnerability could possibly allow code execution on the local system whenthe report is opened in Memory Analyzer. | |||||
