Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-20807 | 1 Cybozu | 1 Remote Service Manager | 2021-10-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20805 | 1 Cybozu | 1 Remote Service Manager | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20800 | 1 Cybozu | 1 Remote Service Manager | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20799 | 1 Cybozu | 1 Remote Service Manager | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20798 | 1 Cybozu | 1 Remote Service Manager | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20797 | 1 Cybozu | 1 Remote Service Manager | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox. | |||||
CVE-2021-20128 | 1 Draytek | 1 Vigorconnect | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized. | |||||
CVE-2021-42223 | 1 Online Dj Booking Management System Project | 1 Online Dj Booking Management System | 2021-10-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php. | |||||
CVE-2021-41354 | 1 Microsoft | 1 Dynamics 365 | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
CVE-2021-40457 | 1 Microsoft | 1 Dynamics 365 | 2021-10-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | |||||
CVE-2021-40292 | 1 Dzzoffice | 1 Dzzoffice | 2021-10-19 | 3.5 LOW | 5.4 MEDIUM |
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter. | |||||
CVE-2021-38183 | 1 Sap | 1 Netweaver | 2021-10-18 | 4.3 MEDIUM | 6.1 MEDIUM |
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability. | |||||
CVE-2021-42134 | 1 Django-unicorn | 1 Unicorn | 2021-10-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053. | |||||
CVE-2021-24576 | 1 Techearty | 1 Easy Accordion | 2021-10-18 | 3.5 LOW | 5.4 MEDIUM |
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion. | |||||
CVE-2021-40191 | 1 Dzzoffice | 1 Dzzoffice | 2021-10-18 | 3.5 LOW | 5.4 MEDIUM |
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type of output data in webroot/dzz/attach/controller.php. | |||||
CVE-2021-40542 | 1 Os4ed | 1 Opensis | 2021-10-18 | 4.3 MEDIUM | 6.1 MEDIUM |
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php. | |||||
CVE-2021-38699 | 1 Tastyigniter | 1 Tastyigniter | 2021-10-18 | 3.5 LOW | 5.4 MEDIUM |
TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs. | |||||
CVE-2021-20825 | 2 Ec-cube, Shiro8 | 2 Ec-cube, List \(order Management\) Item Change | 2021-10-18 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-40888 | 1 Projectsend | 1 Projectsend | 2021-10-18 | 3.5 LOW | 5.4 MEDIUM |
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code. | |||||
CVE-2021-24275 | 1 Supsystic | 1 Popup | 2021-10-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue |