Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1682 1 Facturascripts 1 Facturascripts 2022-05-20 4.3 MEDIUM 6.1 MEDIUM
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser
CVE-2022-28920 1 Moecraft 1 Tieba-cloud-sign 2022-05-20 3.5 LOW 4.8 MEDIUM
Tieba-Cloud-Sign v4.9 was discovered to contain a cross-site scripting (XSS) vulnerability via the function strip_tags.
CVE-2021-42648 1 Coder 1 Code-server 2022-05-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.
CVE-2022-30057 1 Shopwind 1 Shopwind 2022-05-20 3.5 LOW 5.4 MEDIUM
Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.
CVE-2021-31330 1 Reviewboard 1 Review Board 2022-05-20 3.5 LOW 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
CVE-2021-28290 1 Identityserver4.admin Project 1 Identityserver4.admin 2022-05-20 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
CVE-2022-23137 1 Zte 2 Zxcdn, Zxcdn Firmware 2022-05-19 4.3 MEDIUM 6.1 MEDIUM
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
CVE-2022-22320 1 Ibm 1 Qradar Security Information And Event Manager 2022-05-19 3.5 LOW 4.8 MEDIUM
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367.
CVE-2022-27656 1 Sap 3 Netweaver As Abap Kernel, Netweaver As Abap Krnl64uc, Webdispatcher 2022-05-19 4.3 MEDIUM 6.1 MEDIUM
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2021-39059 1 Ibm 1 Jazz Foundation 2022-05-19 3.5 LOW 5.4 MEDIUM
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.
CVE-2022-29610 1 Sap 1 Netweaver Application Server Abap 2022-05-18 3.5 LOW 5.4 MEDIUM
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
CVE-2021-43081 1 Fortinet 2 Fortios, Fortiproxy 2022-05-18 4.3 MEDIUM 6.1 MEDIUM
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
CVE-2022-1433 1 Gitlab 1 Gitlab 2022-05-18 4.3 MEDIUM 6.1 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.
CVE-2022-30278 1 Synopsys 1 Black Duck Hub 2022-05-18 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation to supply content. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.
CVE-2022-28077 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2022-05-17 4.3 MEDIUM 6.1 MEDIUM
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
CVE-2022-28078 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2022-05-17 4.3 MEDIUM 6.1 MEDIUM
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
CVE-2022-29976 1 Altn 1 Mdaemon 2022-05-17 3.5 LOW 5.4 MEDIUM
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .
CVE-2022-29975 1 Altn 1 Mdaemon 2022-05-17 3.5 LOW 5.4 MEDIUM
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .
CVE-2022-1567 1 Wp-js Project 1 Wp-js 2022-05-17 4.3 MEDIUM 6.1 MEDIUM
The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in versions up to, and including, 2.0.6.
CVE-2021-43712 1 Employee Daily Task Management System Project 1 Employee Daily Task Management System 2022-05-17 3.5 LOW 5.4 MEDIUM
Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.