Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-5472 | 1 Broadcom | 1 Host-based Intrusion Prevention System | 2021-04-09 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Server component in CA Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows remote attackers to inject arbitrary web script or HTML via requests that are written to logs for later display in the log viewer. | |||||
CVE-2007-6406 | 1 Broadcom | 1 Etrust Threat Management Console | 2021-04-09 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in CA (formerly Computer Associates) eTrust Threat Management Console allow remote attackers to inject arbitrary web script or HTML via the IP Address field and other unspecified fields. | |||||
CVE-2021-24157 | 1 Themeisle | 1 Orbit Fox | 2021-04-09 | 3.5 LOW | 5.4 MEDIUM |
Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious. | |||||
CVE-2014-9412 | 1 Microfocus | 1 Access Manager | 2021-04-09 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter to roma/jsp/debug/debug.jsp or (2) an arbitrary parameter in a debug.DumpAll action to nps/servlet/webacc, a different issue than CVE-2014-5216. | |||||
CVE-2014-5216 | 1 Microfocus | 1 Access Manager | 2021-04-09 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in a dev.Empty action to nps/servlet/webacc, (2) the error parameter to nidp/jsp/x509err.jsp, (3) the lang parameter to sslvpn/applet_agent.jsp, or (4) the secureLoggingServersA parameter to roma/system/cntl, a different issue than CVE-2014-9412. | |||||
CVE-2007-5923 | 1 Broadcom | 1 Etrust Siteminder | 2021-04-09 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than CVE-2005-2204. | |||||
CVE-2018-7680 | 1 Microfocus | 1 Solutions Business Manager | 2021-04-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values. | |||||
CVE-2018-7681 | 1 Microfocus | 1 Solutions Business Manager | 2021-04-09 | 3.5 LOW | 4.8 MEDIUM |
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system. | |||||
CVE-2021-24180 | 1 Never5 | 1 Related Posts | 2021-04-09 | 3.5 LOW | 5.4 MEDIUM |
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL. | |||||
CVE-2021-24177 | 1 Webdesi9 | 1 File Manager | 2021-04-09 | 3.5 LOW | 5.4 MEDIUM |
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response. | |||||
CVE-2015-2944 | 1 Apache | 2 Sling Api, Sling Servlets Post | 2021-04-09 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse. | |||||
CVE-2021-24168 | 1 Easy Contact Form Pro Project | 1 Easy Contact Form Pro | 2021-04-09 | 3.5 LOW | 5.4 MEDIUM |
The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator. | |||||
CVE-2021-30150 | 1 Ocproducts | 1 Composr | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Composr 10.0.36 allows XSS in an XML script. | |||||
CVE-2021-30125 | 1 Jamf | 1 Jamf | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376. | |||||
CVE-2020-17453 | 1 Wso2 | 8 Api Manager, Api Manager Analytics, Api Microgateway and 5 more | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | |||||
CVE-2021-30109 | 1 Froala | 1 Froala Editor | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module. | |||||
CVE-2020-13418 | 1 Openiam | 1 Openiam | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature. | |||||
CVE-2021-24156 | 1 Testimonial Rotator Project | 1 Testimonial Rotator | 2021-04-08 | 3.5 LOW | 5.4 MEDIUM |
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation | |||||
CVE-2020-4792 | 1 Ibm | 1 Edge Application Manager | 2021-04-08 | 3.5 LOW | 5.4 MEDIUM |
IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 189441. | |||||
CVE-2020-4997 | 1 Ibm | 1 Infosphere Information Server | 2021-04-08 | 3.5 LOW | 5.4 MEDIUM |
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192914 |