Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-4950 | 1 Machform | 1 Machform | 2021-07-01 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter. | |||||
CVE-2020-18668 | 1 Webport | 1 Web Port | 2021-06-30 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls. | |||||
CVE-2020-21783 | 1 Ibos | 1 Ibos | 2021-06-30 | 4.3 MEDIUM | 6.1 MEDIUM |
In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter. | |||||
CVE-2021-33348 | 1 Jfinal | 1 Jfinal | 2021-06-30 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases. | |||||
CVE-2021-23398 | 1 React-bootstrap-table Project | 1 React-bootstrap-table | 2021-06-30 | 4.3 MEDIUM | 6.1 MEDIUM |
All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output. | |||||
CVE-2021-29677 | 1 Ibm | 1 Security Verify | 2021-06-30 | 3.5 LOW | 5.4 MEDIUM |
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
CVE-2021-20477 | 1 Ibm | 1 Planning Analytics | 2021-06-30 | 3.5 LOW | 5.4 MEDIUM |
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196949. | |||||
CVE-2021-29953 | 1 Mozilla | 1 Firefox | 2021-06-30 | 4.3 MEDIUM | 6.1 MEDIUM |
A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3. | |||||
CVE-2021-25656 | 1 Avaya | 1 Aura Experience Portal | 2021-06-30 | 3.5 LOW | 5.4 MEDIUM |
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix). | |||||
CVE-2020-23710 | 1 Limesurvey | 1 Limesurvey | 2021-06-29 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. | |||||
CVE-2021-35210 | 1 Contao | 1 Contao | 2021-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end. | |||||
CVE-2021-21441 | 1 Otrs | 1 Otrs | 2021-06-29 | 4.3 MEDIUM | 7.5 HIGH |
There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions. | |||||
CVE-2021-32644 | 1 Ampache | 1 Ampache | 2021-06-29 | 3.5 LOW | 5.4 MEDIUM |
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3. | |||||
CVE-2021-21422 | 1 Mongo-express Project | 1 Mongo-express | 2021-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a cell grows larger than supported size, clicking on a row will show full document unescaped, however this needs admin interaction on cell. 2: Data cells identified as media will be rendered as media, without being sanitized. Example of different renders: image, audio, video, etc. As an example of type 1 attack, an unauthorized user who only can send a large amount of data in a field of a document may use a payload with embedded javascript. This could send an export of a collection to the attacker without even an admin knowing. Other types of attacks such as dropping a database\collection are possible. | |||||
CVE-2018-14683 | 1 Paessler | 1 Prtg Network Monitor | 2021-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI. | |||||
CVE-2016-5078 | 1 Paessler | 1 Prtg Network Monitor | 2021-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Paessler PRTG before 16.2.24.4045 has XSS via SNMP. | |||||
CVE-2021-20741 | 1 Hitachi | 1 Application Server V10 Manual | 2021-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) version 10-11-01 and earlier) allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2020-18661 | 1 Gnuboard | 1 Gnuboard5 | 2021-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php. | |||||
CVE-2020-18663 | 1 Gnuboard | 1 Gnuboard5 | 2021-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php. | |||||
CVE-2020-18657 | 1 Get-simple | 1 Getsimplecms | 2021-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function. |