Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-15875 1 Dlink 2 Dir-615, Dir-615 Firmware 2021-04-23 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
CVE-2018-15874 1 Dlink 2 Dir-615, Dir-615 Firmware 2021-04-23 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
CVE-2018-16605 1 Dlink 2 Dir-600m, Dir-600m Firmware 2021-04-23 3.5 LOW 5.4 MEDIUM
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
CVE-2021-29370 1 Cheetah Browser Project 1 Cheetah Browser 2021-04-23 4.3 MEDIUM 6.1 MEDIUM
A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent scheme. This resulted in Cross-site scripting on the cheetah browser in any website.
CVE-2019-11017 1 Dlink 2 Di-524, Di-524 Firmware 2021-04-23 3.5 LOW 4.8 MEDIUM
On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.
CVE-2020-28141 1 Online Discussion Forum Project 1 Online Discussion Forum 2021-04-22 3.5 LOW 5.4 MEDIUM
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
CVE-2017-3890 1 Blackberry 2 Appliance-x, Workspaces Vapp 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious link.
CVE-2019-19293 1 Siemens 2 Sinvr 3 Central Control Server, Sinvr 3 Video Server 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains a reflected Cross-site Scripting (XSS) vulnerability that could allow an unauthenticated remote attacker to steal sensitive data or execute administrative actions on behalf of a legitimate administrator of the CCS web interface.
CVE-2019-19294 1 Siemens 2 Sinvr 3 Central Control Server, Sinvr 3 Video Server 2021-04-22 3.5 LOW 5.4 MEDIUM
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains multiple stored Cross-site Scripting (XSS) vulnerabilities in several input fields. This could allow an authenticated remote attacker to inject malicious JavaScript code into the CCS web application that is later executed in the browser context of any other user who views the relevant CCS web content.
CVE-2019-17663 1 D-link 2 Dir-866l, Dir-866l Firmware 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.
CVE-2021-31551 1 Mediawiki 1 Mediawiki 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related query parameters allowed for XSS on certain PageForms-managed MediaWiki pages.
CVE-2021-29399 2 Php, Xmbforum2 2 Php, Xmb 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.
CVE-2021-31327 1 Remoteclinic 1 Remote Clinic 2021-04-22 3.5 LOW 5.4 MEDIUM
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
CVE-2021-31329 1 Remoteclinic 1 Remote Clinic 2021-04-22 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
CVE-2021-26030 1 Joomla 1 Joomla\! 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
CVE-2021-26582 3 Hp, Microsoft, Redhat 4 Hp-ux, Icewall Sso Dgfw, Windows and 1 more 2021-04-22 4.3 MEDIUM 6.1 MEDIUM
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).
CVE-2021-27370 1 Monicahq 1 Monica 2021-04-22 3.5 LOW 5.4 MEDIUM
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
CVE-2020-29247 1 Wondercms 1 Wondercms 2021-04-22 3.5 LOW 4.8 MEDIUM
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.
CVE-2008-6495 1 Zirkon Box 1 Yappa-ng 2021-04-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
CVE-2020-29593 1 Orchardproject 1 Orchard 2021-04-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to add a XSS payload that will execute when users attempt to upload a disallowed file type, causing the error to display.