Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-30058 1 Eng 1 Knowage 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter.
CVE-2021-30056 1 Eng 1 Knowage 2021-04-08 3.5 LOW 5.4 MEDIUM
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.
CVE-2021-24152 1 Sygnoos 1 Popup Builder 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
CVE-2021-30074 1 Docsifyjs 1 Docsify 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character.
CVE-2020-8789 1 Composr Project 1 Composr 2021-04-08 3.5 LOW 5.4 MEDIUM
Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.
CVE-2021-20685 1 Daifukuya 1 Kagemai 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20686 1 Daifukuya 1 Kagemai 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20689 1 Yomi-search Project 1 Yomi-search 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20690 1 Yomi-search Project 1 Yomi-search 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20691 1 Yomi-search Project 1 Yomi-search 2021-04-08 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-29661 1 Softing 1 Opc Toolbox 2021-04-07 3.5 LOW 5.4 MEDIUM
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
CVE-2020-9995 1 Apple 1 Macos Server 2021-04-07 5.8 MEDIUM 6.1 MEDIUM
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.
CVE-2019-6504 1 Broadcom 1 Automic Workload Automation 2021-04-07 4.3 MEDIUM 6.1 MEDIUM
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.
CVE-2021-22196 1 Gitlab 1 Gitlab 2021-04-07 3.5 LOW 5.4 MEDIUM
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.
CVE-2021-30003 1 Nokia 2 G-120w-f, G-120w-f Firmware 2021-04-07 3.5 LOW 4.8 MEDIUM
An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.
CVE-2021-28047 1 Devolutions 1 Remote Desktop Manager 2021-04-06 3.5 LOW 5.4 MEDIUM
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
CVE-2021-23006 1 F5 1 Big-iq Centralized Management 2021-04-06 4.3 MEDIUM 6.1 MEDIUM
On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVE-2021-23922 1 Devolutions 1 Remote Desktop Manager 2021-04-06 3.5 LOW 5.4 MEDIUM
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.
CVE-2021-23925 1 Devolutions 1 Devolutions Server 2021-04-06 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
CVE-2012-1254 1 Segue Project 1 Segue 2021-04-06 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.