Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-8031 | 1 Opensuse | 1 Open Build Service | 2021-02-17 | 3.5 LOW | 5.4 MEDIUM |
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8. | |||||
CVE-2021-20654 | 1 Wekan Project | 1 Wekan | 2021-02-16 | 3.5 LOW | 5.4 MEDIUM |
Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site. | |||||
CVE-2021-26549 | 1 Smartfoxserver | 1 Smartfoxserver | 2021-02-16 | 3.5 LOW | 5.4 MEDIUM |
An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site. | |||||
CVE-2020-35125 | 1 Acquia | 1 Mautic | 2021-02-16 | 6.8 MEDIUM | 9.6 CRITICAL |
A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept). | |||||
CVE-2021-21023 | 1 Magento | 1 Magento | 2021-02-16 | 3.5 LOW | 4.8 MEDIUM |
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting vulnerability in the admin console. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Access to the admin console is required for successful exploitation. | |||||
CVE-2021-21030 | 1 Magento | 1 Magento | 2021-02-16 | 4.3 MEDIUM | 8.1 HIGH |
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-site scripting (XSS) in the customer address upload feature. Successful exploitation could lead to arbitrary JavaScript execution in the victim's browser. Exploitation of this issue requires user interaction. | |||||
CVE-2021-20645 | 1 Elecom | 2 Wrc-300febk-a, Wrc-300febk-a Firmware | 2021-02-14 | 4.3 MEDIUM | 5.4 MEDIUM |
Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors. | |||||
CVE-2018-8006 | 1 Apache | 1 Activemq | 2021-02-13 | 4.3 MEDIUM | 6.1 MEDIUM |
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter. | |||||
CVE-2020-24842 | 1 Sdgc | 1 Pnpscada | 2021-02-12 | 4.3 MEDIUM | 6.1 MEDIUM |
PNPSCADA 2.200816204020 allows cross-site scripting (XSS), which can execute arbitrary JavaScript in the victim's browser. | |||||
CVE-2021-23327 | 1 Fusioncharts | 1 Apexcharts | 2021-02-12 | 4.3 MEDIUM | 6.3 MEDIUM |
The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields. | |||||
CVE-2020-22839 | 1 B2evolution | 1 B2evolution Cms | 2021-02-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter. | |||||
CVE-2009-5031 | 2 Opensuse, Trustwave | 2 Opensuse, Modsecurity | 2021-02-12 | 4.3 MEDIUM | N/A |
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header. | |||||
CVE-2020-4768 | 1 Ibm | 2 Business Automation Workflow, Case Manager | 2021-02-12 | 3.5 LOW | 5.4 MEDIUM |
IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188907. | |||||
CVE-2021-23881 | 1 Mcafee | 1 Endpoint Security | 2021-02-11 | 3.5 LOW | 4.8 MEDIUM |
A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the policy. | |||||
CVE-2020-29171 | 1 Tipsandtricks-hq | 1 Wp Security \& Firewall | 2021-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress. | |||||
CVE-2020-35572 | 1 Adminer | 1 Adminer | 2021-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Adminer through 4.7.8 allows XSS via the history parameter to the default URI. | |||||
CVE-2021-26916 | 1 Nopcommerce | 1 Nopcommerce | 2021-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter. | |||||
CVE-2020-29021 | 1 Secomea | 8 Gatemanager 4250, Gatemanager 4250 Firmware, Gatemanager 4260 and 5 more | 2021-02-10 | 3.5 LOW | 4.8 MEDIUM |
A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3. | |||||
CVE-2021-3258 | 1 Qa-themes | 1 Q2a Ultimate Seo | 2021-02-10 | 3.5 LOW | 5.4 MEDIUM |
Question2Answer Q2A Ultimate SEO Version 1.3 is affected by cross-site scripting (XSS), which may lead to arbitrary remote code execution. | |||||
CVE-2020-13248 | 1 Boolebox | 1 Boolebox | 2021-02-10 | 3.5 LOW | 5.4 MEDIUM |
BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx. |