Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-36510 | 1 Codetipi | 1 15zine | 2022-03-07 | 4.3 MEDIUM | 6.1 MEDIUM |
The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-25114 | 1 Event Management Project | 1 Event Management | 2022-03-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php. | |||||
CVE-2020-14502 | 1 Rockwellautomation | 4 1734-aentr Point I\/o Dual Port Network Adaptor Series B, 1734-aentr Point I\/o Dual Port Network Adaptor Series B Firmware, 1734-aentr Point I\/o Dual Port Network Adaptor Series C and 1 more | 2022-03-07 | 4.3 MEDIUM | 6.1 MEDIUM |
The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface. | |||||
CVE-2021-24898 | 1 Editable-table Project | 1 Editable Table | 2022-03-07 | 3.5 LOW | 4.8 MEDIUM |
The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-24901 | 1 Securemoz | 1 Security Audit | 2022-03-07 | 3.5 LOW | 4.8 MEDIUM |
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24903 | 1 Codeasily | 1 Grand Flagallery | 2022-03-07 | 3.5 LOW | 4.8 MEDIUM |
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24920 | 1 Statcounter | 1 Statcounter | 2022-03-07 | 3.5 LOW | 4.8 MEDIUM |
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-43943 | 1 Atlassian | 1 Jira Service Management | 2022-03-07 | 3.5 LOW | 4.8 MEDIUM |
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0. | |||||
CVE-2021-45229 | 1 Apache | 1 Airflow | 2022-03-04 | 4.3 MEDIUM | 6.1 MEDIUM |
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below. | |||||
CVE-2021-29216 | 1 Hpe | 1 Oneview Global Dashboard | 2022-03-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard. | |||||
CVE-2022-24708 | 1 Anuko | 1 Time Tracker | 2022-03-04 | 3.5 LOW | 5.4 MEDIUM |
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Tracker versions prior to 1.20.0.5646 was not escaping primary group name for display. Because of that, it was possible for a logged in user to modify primary group name with elements of JavaScript. Such script could then be executed in user browser on subsequent requests on pages where primary group name was displayed. This is vulnerability has been fixed in version 1.20.0.5646. Users who are unable to upgrade may modify ttUser.class.php to use an additional call to htmlspecialchars when printing group name. | |||||
CVE-2021-43062 | 1 Fortinet | 1 Fortimail | 2022-03-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service. | |||||
CVE-2022-0394 | 1 Livehelperchat | 1 Live Helper Chat | 2022-03-04 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |||||
CVE-2022-25256 | 6 Hpe, Ibm, Linux and 3 more | 6 Hp-ux Ipfilter, Aix, Linux Kernel and 3 more | 2022-03-04 | 4.3 MEDIUM | 6.1 MEDIUM |
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL. | |||||
CVE-2022-25259 | 1 Jetbrains | 1 Hub | 2022-03-03 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS. | |||||
CVE-2022-24347 | 1 Jetbrains | 1 Youtrack | 2022-03-03 | 3.5 LOW | 5.4 MEDIUM |
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. | |||||
CVE-2022-24344 | 1 Jetbrains | 1 Youtrack | 2022-03-03 | 3.5 LOW | 5.4 MEDIUM |
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. | |||||
CVE-2022-24339 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 3.5 LOW | 5.4 MEDIUM |
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. | |||||
CVE-2022-24338 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. | |||||
CVE-2022-24612 | 1 Eyesofnetwork | 1 Eyesofnetwork | 2022-03-03 | 3.5 LOW | 5.4 MEDIUM |
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS. |