Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-30058 | 1 Eng | 1 Knowage | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter. | |||||
CVE-2021-30056 | 1 Eng | 1 Knowage | 2021-04-08 | 3.5 LOW | 5.4 MEDIUM |
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage. | |||||
CVE-2021-24152 | 1 Sygnoos | 1 Popup Builder | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting. | |||||
CVE-2021-30074 | 1 Docsifyjs | 1 Docsify | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character. | |||||
CVE-2020-8789 | 1 Composr Project | 1 Composr | 2021-04-08 | 3.5 LOW | 5.4 MEDIUM |
Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration. | |||||
CVE-2021-20685 | 1 Daifukuya | 1 Kagemai | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20686 | 1 Daifukuya | 1 Kagemai | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20689 | 1 Yomi-search Project | 1 Yomi-search | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20690 | 1 Yomi-search Project | 1 Yomi-search | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-20691 | 1 Yomi-search Project | 1 Yomi-search | 2021-04-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-29661 | 1 Softing | 1 Opc Toolbox | 2021-04-07 | 3.5 LOW | 5.4 MEDIUM |
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it. | |||||
CVE-2020-9995 | 1 Apple | 1 Macos Server | 2021-04-07 | 5.8 MEDIUM | 6.1 MEDIUM |
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting. | |||||
CVE-2019-6504 | 1 Broadcom | 1 Automic Workload Automation | 2021-04-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object. | |||||
CVE-2021-22196 | 1 Gitlab | 1 Gitlab | 2021-04-07 | 3.5 LOW | 5.4 MEDIUM |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name. | |||||
CVE-2021-30003 | 1 Nokia | 2 G-120w-f, G-120w-f Firmware | 2021-04-07 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address. | |||||
CVE-2021-28047 | 1 Devolutions | 1 Remote Desktop Manager | 2021-04-06 | 3.5 LOW | 5.4 MEDIUM |
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields. | |||||
CVE-2021-23006 | 1 F5 | 1 Big-iq Centralized Management | 2021-04-06 | 4.3 MEDIUM | 6.1 MEDIUM |
On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated. | |||||
CVE-2021-23922 | 1 Devolutions | 1 Remote Desktop Manager | 2021-04-06 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews. | |||||
CVE-2021-23925 | 1 Devolutions | 1 Devolutions Server | 2021-04-06 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document. | |||||
CVE-2012-1254 | 1 Segue Project | 1 Segue | 2021-04-06 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |