Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2122 1 Jenkins 1 Brakeman 2020-02-14 3.5 LOW 5.4 MEDIUM
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.
CVE-2019-4431 1 Ibm 1 Rational Publishing Engine 2020-02-14 3.5 LOW 5.4 MEDIUM
IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162888.
CVE-2020-2113 1 Jenkins 1 Git Parameter 2020-02-14 3.5 LOW 5.4 MEDIUM
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
CVE-2020-2112 1 Jenkins 1 Git Parameter 2020-02-14 3.5 LOW 5.4 MEDIUM
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
CVE-2020-8089 1 Piwigo 1 Piwigo 2020-02-14 3.5 LOW 5.4 MEDIUM
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
CVE-2020-2111 1 Jenkins 1 Subversion 2020-02-14 3.5 LOW 5.4 MEDIUM
Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.
CVE-2013-1410 1 Perforce 1 P4web 2020-02-14 4.3 MEDIUM 6.1 MEDIUM
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
CVE-2020-0693 1 Microsoft 1 Sharepoint Enterprise Server 2020-02-13 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0694.
CVE-2020-0694 1 Microsoft 1 Sharepoint Enterprise Server 2020-02-13 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0693.
CVE-2019-1020007 1 Owasp 1 Dependency-track 2020-02-13 3.5 LOW 5.4 MEDIUM
Dependency-Track before 3.5.1 allows XSS.
CVE-2012-6449 1 Cpanel 2 Cpanel, Whm 2020-02-13 3.5 LOW 5.4 MEDIUM
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
CVE-2012-4519 1 Zenphoto 1 Zenphoto 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.
CVE-2012-6720 1 Socialengine 1 Socialengine 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*.
CVE-2014-3827 1 Mybb 1 Mybb 2020-02-12 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser action or the name parameter in an (4) edit action in the user-user module or the (5) editprofile action to modcp.php.
CVE-2013-1760 1 Thebuggenie 1 The Bug Genie 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities
CVE-2020-5317 1 Dell 1 Emc Elastic Cloud Storage 2020-02-12 3.5 LOW 4.8 MEDIUM
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
CVE-2011-3642 1 Flowplayer 1 Flowplayer Flash 2020-02-12 6.8 MEDIUM 9.6 CRITICAL
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
CVE-2013-5988 1 Semperplugins 1 All In One Seo Pack 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.
CVE-2019-15619 1 Nextcloud 3 Deck, Nextcloud Server, Talk 2020-02-12 3.5 LOW 4.8 MEDIUM
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
CVE-2019-15614 1 Nextcloud 1 Nextcloud 2020-02-12 3.5 LOW 5.4 MEDIUM
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.