Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-29387 1 Equipment Inventory System Project 1 Equipment Inventory System 2021-05-05 3.5 LOW 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.
CVE-2020-21993 1 Wems 1 Enterprise Manager 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.
CVE-2021-29159 1 Sonatype 1 Nexus Repository Manager 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.
CVE-2020-17999 1 1234n 1 Minicms 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
CVE-2021-25810 1 Mercusys 2 Mercury X18g, Mercury X18g Firmware 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
CVE-2019-25027 1 Vaadin 2 Flow, Vaadin 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL
CVE-2019-25028 1 Vaadin 1 Vaadin 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vector
CVE-2021-1456 1 Cisco 1 Firepower Management Center 2021-05-05 3.5 LOW 4.8 MEDIUM
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
CVE-2021-1457 1 Cisco 1 Firepower Management Center 2021-05-05 3.5 LOW 4.8 MEDIUM
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
CVE-2021-1458 1 Cisco 1 Firepower Management Center 2021-05-05 3.5 LOW 4.8 MEDIUM
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
CVE-2020-22808 1 Fecmall Project 1 Fecmall 2021-05-05 4.3 MEDIUM 6.1 MEDIUM
An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
CVE-2021-1455 1 Cisco 1 Firepower Management Center 2021-05-05 3.5 LOW 4.8 MEDIUM
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
CVE-2018-20339 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
CVE-2018-19288 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
CVE-2018-19921 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
CVE-2018-18715 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
CVE-2018-18716 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
CVE-2018-18262 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
CVE-2020-13285 1 Gitlab 1 Gitlab 2021-05-03 3.5 LOW 5.4 MEDIUM
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
CVE-2021-20550 3 Ibm, Linux, Microsoft 4 Aix, Content Navigator, Linux Kernel and 1 more 2021-05-03 3.5 LOW 5.4 MEDIUM
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199168.