Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-13312 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
CVE-2018-13309 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
CVE-2018-13308 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
CVE-2018-13310 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
CVE-2018-6076 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
CVE-2018-19469 1 Articlecms Project 1 Articlecms 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
CVE-2018-19547 1 Jtbc 1 Jtbc Php 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.
CVE-2018-19564 1 Goldplugins 1 Easy Testimonials 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
CVE-2018-19433 1 Showdoc 1 Showdoc 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
CVE-2014-3681 2 Jenkins, Redhat 2 Jenkins, Openshift 2018-12-18 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-19324 1 Kimsq 1 Rb 2018-12-17 3.5 LOW 5.4 MEDIUM
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI.
CVE-2018-16619 1 Sonatype 1 Nexus Repository Manager 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-19340 1 Guriddo 1 Form Php 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
CVE-2018-0695 1 Usvn 1 Usvn 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-19188 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
CVE-2018-19190 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
CVE-2018-19186 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
CVE-2018-19187 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
CVE-2018-19189 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
CVE-2018-8600 1 Microsoft 1 Azure App Service On Azure Stack 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.
CVE-2018-19352 1 Jupyter 1 Notebook 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
CVE-2018-19350 1 Seacms 1 Seacms 2018-12-17 3.5 LOW 5.4 MEDIUM
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
CVE-2018-0697 1 Metabase 1 Metabase 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0699 1 Hyuki 1 Yukiwiki 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-14935 1 Polycom 2 Trio 8500, Trio 8500 Firmware 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
CVE-2018-0687 1 Neo 2 Debun Imap, Debun Pop 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-19287 1 Ninjaforma 1 Ninja Forms 2018-12-14 4.3 MEDIUM 6.1 MEDIUM
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
CVE-2018-6081 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-14 4.3 MEDIUM 6.1 MEDIUM
XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
CVE-2018-8605 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8606, CVE-2018-8607, CVE-2018-8608.
CVE-2018-8606 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8607, CVE-2018-8608.
CVE-2018-8607 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8608.
CVE-2018-8608 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8607.
CVE-2018-8547 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
CVE-2018-19195 1 Xiaocms 1 Xiaocms 2018-12-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.
CVE-2018-19170 1 Jpress 1 Jpress 2018-12-13 3.5 LOW 4.8 MEDIUM
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter.
CVE-2018-19193 1 Xiaocms 1 Xiaocms 2018-12-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.
CVE-2018-19080 2 Foscam, Opticam 6 C2, C2 Application Firmware, C2 System Firmware and 3 more 2018-12-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS.
CVE-2018-19178 1 Jeesns 1 Jeesns 2018-12-13 3.5 LOW 5.4 MEDIUM
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
CVE-2018-19092 1 Yzmcms 1 Yzmcms 2018-12-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.
CVE-2018-17184 1 Apache 1 Syncope 2018-12-13 3.5 LOW 5.4 MEDIUM
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.
CVE-2018-19206 2 Debian, Roundcube 2 Debian Linux, Roundcube 2018-12-13 4.3 MEDIUM 6.1 MEDIUM
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
CVE-2018-10586 1 Netgain-systems 1 Enterprise Manager 2018-12-12 3.5 LOW 4.8 MEDIUM
NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions before 10.1.12.
CVE-2018-19141 2 Debian, Otrs 2 Debian Linux, Open Ticket Request System 2018-12-12 3.5 LOW 4.8 MEDIUM
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
CVE-2018-19142 1 Otrs 1 Open Ticket Request System 2018-12-12 3.5 LOW 4.8 MEDIUM
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
CVE-2018-15707 1 Advantech 1 Webaccess 2018-12-12 3.5 LOW 5.4 MEDIUM
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
CVE-2018-19056 1 Ipandao 1 Editor.md 2018-12-12 4.3 MEDIUM 6.1 MEDIUM
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
CVE-2018-19057 1 Sparksuite 1 Simplemde 2018-12-12 4.3 MEDIUM 6.1 MEDIUM
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
CVE-2018-18775 1 Microstrategy 1 Microstrategy Web 2018-12-12 4.3 MEDIUM 6.1 MEDIUM
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.
CVE-2018-18776 1 Microstrategy 1 Microstrategy Web 2018-12-12 4.3 MEDIUM 6.1 MEDIUM
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.
CVE-2018-19131 1 Squid-cache 1 Squid 2018-12-11 4.3 MEDIUM 6.1 MEDIUM
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.