Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-28249 | 1 Joplin Project | 1 Joplin | 2020-11-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. | |||||
CVE-2020-15952 | 1 Immuta | 1 Immuta | 2020-11-12 | 6.0 MEDIUM | 9.0 CRITICAL |
Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS. | |||||
CVE-2020-5940 | 1 F5 | 13 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 10 more | 2020-11-12 | 3.5 LOW | 5.4 MEDIUM |
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.3, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility. | |||||
CVE-2020-22158 | 1 Mediakind | 2 Rx8200, Rx8200 Firmware | 2020-11-12 | 4.3 MEDIUM | 6.1 MEDIUM |
MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code. | |||||
CVE-2015-9539 | 1 Fast Secure Contact Form Project | 1 Fast Secure Contact Form | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS. | |||||
CVE-2015-9549 | 1 Ocportal | 1 Ocportal | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php. | |||||
CVE-2015-9410 | 1 Blubrry | 1 Powerpress Podcasting | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter. | |||||
CVE-2015-9537 | 1 Imagely | 1 Nextgen Gallery | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template. | |||||
CVE-2015-9229 | 1 Imagely | 1 Nextgen Gallery | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter. | |||||
CVE-2016-11016 | 1 Netgear | 2 Jnr1010, Jnr1010 Firmware | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS. | |||||
CVE-2015-9260 | 1 Bedita | 1 Bedita | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI. | |||||
CVE-2015-9230 | 1 Ait-pro | 1 Bulletproof Security | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter. | |||||
CVE-2019-20443 | 1 Wso2 | 3 Api Manager, Enterprise Integrator, Identity Server | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI. | |||||
CVE-2019-20364 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. | |||||
CVE-2019-20366 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. | |||||
CVE-2019-20440 | 1 Wso2 | 1 Api Manager | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher. | |||||
CVE-2019-20442 | 1 Wso2 | 3 Api Manager, Enterprise Integrator, Identity Server | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI. | |||||
CVE-2019-20441 | 1 Wso2 | 1 Api Manager | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher. | |||||
CVE-2020-24601 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page | |||||
CVE-2019-20438 | 1 Wso2 | 1 Api Manager | 2020-11-10 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been identified in the inline API documentation editor page of the API Publisher. |