Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-27517 1 Foxit 2 Phantompdf, Reader 2021-07-29 4.3 MEDIUM 6.1 MEDIUM
Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).
CVE-2021-27338 1 Faraday 1 Edge 2021-07-29 3.5 LOW 5.4 MEDIUM
Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.
CVE-2021-3135 1 Tagdiv 1 Newspaper 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
CVE-2021-37450 1 Nchsoftware 1 Ivm Attendant 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
CVE-2021-37451 1 Nchsoftware 1 Ivm Attendant 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
CVE-2021-37453 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
CVE-2021-37454 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
CVE-2021-37456 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
CVE-2021-37455 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
CVE-2021-37457 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
CVE-2021-37458 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
CVE-2021-37459 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
CVE-2021-37460 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
CVE-2021-37462 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
CVE-2021-37461 1 Nchsoftware 1 Axon Pbx 2021-07-28 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
CVE-2021-34821 1 Aat 1 Novus Management System 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP 404 error handling implemented. A remote, unauthenticated attacker may be able to exploit the issue by sending malicious HTTP requests to non-existing URIs. The value of the URL path filename is copied into the HTML document as plain text tags.
CVE-2021-34617 1 Aruba 1 Aruba Instant 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.13 and below; Aruba Instant 6.5.x: 6.5.4.13 and below; Aruba Instant 8.3.x: 8.3.0.7 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
CVE-2021-36772 1 Zohocorp 1 Manageengine Admanager Plus 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
CVE-2021-36771 1 Zohocorp 1 Manageengine Admanager Plus 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
CVE-2021-22723 1 Schneider-electric 12 Evlink City Evc1s22p4, Evlink City Evc1s22p4 Firmware, Evlink City Evc1s7p4 and 9 more 2021-07-28 4.3 MEDIUM 6.1 MEDIUM
A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server.