Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-31373 | 1 Juniper | 28 Junos, Srx100, Srx110 and 25 more | 2021-10-27 | 3.5 LOW | 5.4 MEDIUM |
A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive data and credentials from a web administration session, or hijack another user's active session to perform administrative actions. This issue affects: Juniper Networks Junos OS on SRX Series: 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R3-S8; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S3; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3-S1; 20.3 versions prior to 20.3R2-S1, 20.3R3. | |||||
CVE-2021-24420 | 1 Emarketdesign | 1 Request A Quote | 2021-10-27 | 3.5 LOW | 5.4 MEDIUM |
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table. | |||||
CVE-2019-9508 | 1 Vertiv | 2 Avocent Umg-4000, Avocent Umg-4000 Firmware | 2021-10-26 | 3.5 LOW | 3.5 LOW |
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file within the web application that would execute each time a user browsed to the page. | |||||
CVE-2019-9541 | 1 Telos | 1 Automated Message Handling System | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | |||||
CVE-2021-24679 | 1 Coinmarketstats | 1 Bitcoin \/ Altcoin Payment Gateway For Woocommerce | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-27746 | 1 Hcltechsw | 1 Connections | 2021-10-26 | 3.5 LOW | 5.4 MEDIUM |
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability" | |||||
CVE-2021-35228 | 1 Solarwinds | 1 Database Performance Analyzer | 2021-10-26 | 2.6 LOW | 4.7 MEDIUM |
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim. | |||||
CVE-2015-9526 | 2 Easydigitaldownloads, Sandhillsdev | 2 Reviews, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9525 | 2 Easydigitaldownloads, Sandhillsdev | 2 Recurring Payments, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9528 | 2 Easydigitaldownloads, Sandhillsdev | 2 Software Licensing, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9530 | 2 Easydigitaldownloads, Sandhillsdev | 2 Upload File, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9532 | 2 Easydigitaldownloads, Sandhillsdev | 2 Digital Store, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9524 | 2 Easydigitaldownloads, Sandhillsdev | 2 Recount Earnings, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9522 | 2 Easydigitaldownloads, Sandhillsdev | 2 Qr Code, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9521 | 2 Easydigitaldownloads, Sandhillsdev | 2 Pushover Notifications, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9519 | 2 Easydigitaldownloads, Sandhillsdev | 2 Pdf Stamper, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9517 | 2 Easydigitaldownloads, Sandhillsdev | 2 Manual Purchases, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9533 | 2 Easydigitaldownloads, Sandhillsdev | 2 Lattice, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9535 | 2 Easydigitaldownloads, Sandhillsdev | 2 Shoppette, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
CVE-2015-9515 | 2 Easydigitaldownloads, Sandhillsdev | 2 Htaccess Editor, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The Easy Digital Downloads (EDD) htaccess Editor extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. |