Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-20549 | 3 Ibm, Linux, Microsoft | 4 Aix, Content Navigator, Linux Kernel and 1 more | 2021-05-03 | 3.5 LOW | 5.4 MEDIUM |
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199167. | |||||
CVE-2021-20448 | 3 Ibm, Linux, Microsoft | 4 Aix, Content Navigator, Linux Kernel and 1 more | 2021-05-03 | 3.5 LOW | 5.4 MEDIUM |
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196624. | |||||
CVE-2020-18035 | 1 Jeesns | 1 Jeesns | 2021-05-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.java". | |||||
CVE-2021-31792 | 1 Salesagility | 1 Suitecrm | 2021-05-03 | 3.5 LOW | 5.4 MEDIUM |
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field | |||||
CVE-2021-30227 | 1 Emlog | 1 Emlog | 2021-05-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0. | |||||
CVE-2014-9342 | 1 F5 | 1 Big-ip | 2021-05-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script or HTML by accessing a crafted URL during automatic policy generation. | |||||
CVE-2021-31794 | 1 Directum | 1 Directum | 2021-04-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header. | |||||
CVE-2021-27933 | 1 Pfsense | 1 Pfsense | 2021-04-30 | 4.3 MEDIUM | 6.1 MEDIUM |
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field. | |||||
CVE-2021-28079 | 1 Jamovi | 1 Jamovi | 2021-04-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An attacker can make a .omv (Jamovi) document containing a payload. When opened by victim, the payload is triggered. | |||||
CVE-2010-2250 | 1 Drupal | 1 Drupal | 2021-04-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | |||||
CVE-2020-17542 | 1 Dotcms | 1 Dotcms | 2021-04-30 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component. | |||||
CVE-2021-24237 | 1 Purethemes | 2 Findeo, Realteo | 2021-04-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue. | |||||
CVE-2021-24239 | 1 Genetechsolutions | 1 Pie Register | 2021-04-30 | 4.3 MEDIUM | 6.1 MEDIUM |
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue. | |||||
CVE-2021-22199 | 1 Gitlab | 1 Gitlab | 2021-04-30 | 3.5 LOW | 5.4 MEDIUM |
An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used. | |||||
CVE-2021-24241 | 1 Advancedcustomfields | 1 Advanced Custom Fields | 2021-04-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page. | |||||
CVE-2021-29459 | 1 Xwiki | 1 Xwiki | 2021-04-29 | 4.3 MEDIUM | 6.1 MEDIUM |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject scripts in XWiki versions prior to 12.6.3 and 12.8. Unregistred users can fill simple text fields. Registered users can fill in their personal information and (if they have edit rights) fill the values of static lists using App Within Minutes. There is no easy workaround except upgrading XWiki. The vulnerability has been patched on XWiki 12.8 and 12.6.3. | |||||
CVE-2021-24235 | 1 Boostifythemes | 1 Goto | 2021-04-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue. | |||||
CVE-2021-24232 | 1 Elbtide | 1 Advanced Booking Calendar | 2021-04-29 | 3.5 LOW | 5.4 MEDIUM |
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue | |||||
CVE-2021-24233 | 1 Boxystudio | 1 Cooked | 2021-04-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute. | |||||
CVE-2021-24234 | 1 Ivorysearch | 1 Ivory Search | 2021-04-29 | 4.3 MEDIUM | 6.1 MEDIUM |
The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack. |