Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-2122 | 1 Jenkins | 1 Brakeman | 2020-02-14 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data. | |||||
CVE-2019-4431 | 1 Ibm | 1 Rational Publishing Engine | 2020-02-14 | 3.5 LOW | 5.4 MEDIUM |
IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162888. | |||||
CVE-2020-2113 | 1 Jenkins | 1 Git Parameter | 2020-02-14 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission. | |||||
CVE-2020-2112 | 1 Jenkins | 1 Git Parameter | 2020-02-14 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission. | |||||
CVE-2020-8089 | 1 Piwigo | 1 Piwigo | 2020-02-14 | 3.5 LOW | 5.4 MEDIUM |
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page. | |||||
CVE-2020-2111 | 1 Jenkins | 1 Subversion | 2020-02-14 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability. | |||||
CVE-2013-1410 | 1 Perforce | 1 P4web | 2020-02-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities | |||||
CVE-2020-0693 | 1 Microsoft | 1 Sharepoint Enterprise Server | 2020-02-13 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0694. | |||||
CVE-2020-0694 | 1 Microsoft | 1 Sharepoint Enterprise Server | 2020-02-13 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0693. | |||||
CVE-2019-1020007 | 1 Owasp | 1 Dependency-track | 2020-02-13 | 3.5 LOW | 5.4 MEDIUM |
Dependency-Track before 3.5.1 allows XSS. | |||||
CVE-2012-6449 | 1 Cpanel | 2 Cpanel, Whm | 2020-02-13 | 3.5 LOW | 5.4 MEDIUM |
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability. | |||||
CVE-2012-4519 | 1 Zenphoto | 1 Zenphoto | 2020-02-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS. | |||||
CVE-2012-6720 | 1 Socialengine | 1 Socialengine | 2020-02-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*. | |||||
CVE-2014-3827 | 1 Mybb | 1 Mybb | 2020-02-12 | 3.5 LOW | 5.4 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser action or the name parameter in an (4) edit action in the user-user module or the (5) editprofile action to modcp.php. | |||||
CVE-2013-1760 | 1 Thebuggenie | 1 The Bug Genie | 2020-02-12 | 4.3 MEDIUM | 6.1 MEDIUM |
The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities | |||||
CVE-2020-5317 | 1 Dell | 1 Emc Elastic Cloud Storage | 2020-02-12 | 3.5 LOW | 4.8 MEDIUM |
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. | |||||
CVE-2011-3642 | 1 Flowplayer | 1 Flowplayer Flash | 2020-02-12 | 6.8 MEDIUM | 9.6 CRITICAL |
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin. | |||||
CVE-2013-5988 | 1 Semperplugins | 1 All In One Seo Pack | 2020-02-12 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter. | |||||
CVE-2019-15619 | 1 Nextcloud | 3 Deck, Nextcloud Server, Talk | 2020-02-12 | 3.5 LOW | 4.8 MEDIUM |
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project. | |||||
CVE-2019-15614 | 1 Nextcloud | 1 Nextcloud | 2020-02-12 | 3.5 LOW | 5.4 MEDIUM |
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. |