Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-20363 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents. | |||||
CVE-2020-24604 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp | |||||
CVE-2020-24602 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server Properties and Security Audit Viewer JSP page | |||||
CVE-2019-16728 | 2 Cure53, Debian | 2 Dompurify, Debian Linux | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari. | |||||
CVE-2019-20365 | 1 Igniterealtime | 1 Openfire | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. | |||||
CVE-2018-5950 | 4 Canonical, Debian, Gnu and 1 more | 9 Ubuntu Linux, Debian Linux, Mailman and 6 more | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL. | |||||
CVE-2019-7356 | 1 Intelliants | 1 Subrion | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter. | |||||
CVE-2020-28047 | 1 Web-audimex | 1 Audimexee | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage. | |||||
CVE-2020-27691 | 1 Imomobile | 2 Verve Connect Vh510, Verve Connect Vh510 Firmware | 2020-11-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings. | |||||
CVE-2020-2316 | 1 Jenkins | 1 Static Analysis Utilities | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |||||
CVE-2020-2317 | 1 Jenkins | 1 Findbugs | 2020-11-10 | 3.5 LOW | 5.4 MEDIUM |
Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step. | |||||
CVE-2017-14651 | 1 Wso2 | 17 Api Manager, App Manager, Application Server and 14 more | 2020-11-09 | 3.5 LOW | 4.8 MEDIUM |
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |||||
CVE-2020-26505 | 1 Marmind | 1 Marmind | 2020-11-08 | 4.3 MEDIUM | 6.1 MEDIUM |
A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker to perform unauthorized actions in the application on behalf of legitimate users or spread malware via the application. By using the “Assets Upload” function, an attacker can abuse the upload function to upload a malicious PDF file containing a stored XSS. | |||||
CVE-2020-5932 | 1 F5 | 1 Big-ip Application Security Manager | 2020-11-08 | 3.5 LOW | 4.8 MEDIUM |
On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility response and blocking pages. An authenticated user with administrative privileges can specify a response page with any content, including JavaScript code that will be executed when preview is opened. | |||||
CVE-2020-27980 | 1 Genexis | 2 Platinum-4410, Platinum-4410 Firmware | 2020-11-04 | 3.5 LOW | 5.4 MEDIUM |
Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users. | |||||
CVE-2020-27359 | 1 Evms | 1 Redcap | 2020-11-04 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages. | |||||
CVE-2020-27741 | 1 Citadel | 1 Webcit | 2020-11-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread. | |||||
CVE-2020-27957 | 1 Mediawiki | 1 Mediawiki | 2020-11-04 | 3.5 LOW | 5.4 MEDIUM |
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension. | |||||
CVE-2020-25516 | 1 Wso2 | 1 Enterprise Integrator | 2020-11-03 | 3.5 LOW | 5.4 MEDIUM |
WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks. | |||||
CVE-2020-26205 | 1 Sal Project | 1 Sal | 2020-11-03 | 3.5 LOW | 5.4 MEDIUM |
Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view. |