Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-8512 | 1 Icewarp | 1 Icewarp Server | 2020-02-03 | 4.3 MEDIUM | 6.1 MEDIUM |
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter. | |||||
CVE-2014-3718 | 1 Exlibrisgroup | 1 Aleph 500 | 2020-02-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid parameter. | |||||
CVE-2013-3565 | 2 Opensuse, Videolan | 2 Opensuse, Vlc Media Player | 2020-02-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua. | |||||
CVE-2013-4241 | 1 Hitmyserver | 1 Hms Testimonials | 2020-02-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page). | |||||
CVE-2020-8498 | 1 Gistpress Project | 1 Gistpress | 2020-02-03 | 3.5 LOW | 5.4 MEDIUM |
XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability). | |||||
CVE-2018-6464 | 1 Mycolorway | 1 Simditor | 2020-02-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1. | |||||
CVE-2012-6133 | 1 Roundup-tracker | 1 Roundup | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*. | |||||
CVE-2013-2294 | 1 Viewgit Project | 1 Viewgit | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php or (3) Heads table in plates/summary.php. | |||||
CVE-2020-3121 | 1 Cisco | 90 Sf350-48, Sf350-48 Firmware, Sf350-48mp and 87 more | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link and access a specific page. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
CVE-2019-19632 | 1 Bigswitch | 3 Big Cloud Fabric, Big Monitoring Fabric, Multi-cloud Director | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject stored arbitrary JavaScript (XSS), and execute it in the content of authenticated administrators. | |||||
CVE-2020-7910 | 1 Jetbrains | 1 Teamcity | 2020-01-31 | 3.5 LOW | 5.4 MEDIUM |
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. | |||||
CVE-2020-7911 | 1 Jetbrains | 1 Teamcity | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. | |||||
CVE-2020-7913 | 1 Jetbrains | 1 Youtrack | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. | |||||
CVE-2013-3320 | 1 Netapp | 1 Oncommand System Manager | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields. | |||||
CVE-2012-5776 | 1 Dokeos | 1 Dokeos | 2020-01-31 | 3.5 LOW | 5.4 MEDIUM |
Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php. | |||||
CVE-2013-0738 | 1 Chamilo | 1 Chamilo | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php. | |||||
CVE-2013-0739 | 1 Chamilo | 1 Chamilo | 2020-01-31 | 4.3 MEDIUM | 6.1 MEDIUM |
Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script. | |||||
CVE-2013-0161 | 1 Havalite | 1 Havalite | 2020-01-30 | 3.5 LOW | 5.4 MEDIUM |
Havalite CMS 1.1.7 has a stored XSS vulnerability | |||||
CVE-2020-3715 | 1 Magento | 1 Magento | 2020-01-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. | |||||
CVE-2020-3758 | 1 Magento | 1 Magento | 2020-01-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |