Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-18347 | 1 Davical | 1 Davical | 2019-12-14 | 3.5 LOW | 5.4 MEDIUM |
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email. | |||||
CVE-2013-4968 | 1 Puppet | 1 Puppet Enterprise | 2019-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management." | |||||
CVE-2013-6495 | 1 Redhat | 2 Jboss Enterprise Application Platform, Jboss Portal | 2019-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
JBossWeb Bayeux has reflected XSS | |||||
CVE-2019-15935 | 1 Intesync | 1 Solismed | 2019-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Intesync Solismed 3.3sp has XSS. | |||||
CVE-2019-18378 | 1 Symantec | 1 Messaging Gateway | 2019-12-13 | 3.5 LOW | 4.8 MEDIUM |
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy. | |||||
CVE-2019-19748 | 1 Brizoit | 1 Work Time Calendar | 2019-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
The Work Time Calendar app before 4.7.1 for Jira allows XSS. | |||||
CVE-2019-19719 | 3 Linux, Microsoft, Tableau | 3 Linux Kernel, Windows, Tableau Server | 2019-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page. | |||||
CVE-2019-4665 | 1 Ibm | 1 Spectrum Scale | 2019-12-12 | 3.5 LOW | 5.4 MEDIUM |
IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171247. | |||||
CVE-2012-1114 | 3 Debian, Fedoraproject, Ldap-account-manager | 3 Debian Linux, Fedora, Ldap Account Manager | 2019-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php. | |||||
CVE-2019-15007 | 1 Atlassian | 2 Crucible, Fisheye | 2019-12-12 | 3.5 LOW | 4.8 MEDIUM |
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch. | |||||
CVE-2019-15008 | 1 Atlassian | 2 Crucible, Fisheye | 2019-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter. | |||||
CVE-2011-3373 | 1 Drupal | 1 Views Builk Operations | 2019-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack. | |||||
CVE-2017-10673 | 1 Get-simple | 1 Getsimple Cms | 2019-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
admin/profile.php in GetSimple CMS 3.x has XSS in a name field. | |||||
CVE-2019-4226 | 1 Ibm | 1 Cloud Pak System | 2019-12-11 | 3.5 LOW | 5.4 MEDIUM |
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159243. | |||||
CVE-2012-1637 | 1 Drupal | 1 Quick Tabs | 2019-12-11 | 3.5 LOW | 4.8 MEDIUM |
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal. | |||||
CVE-2011-4090 | 1 S9y | 1 Serendipity | 2019-12-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. | |||||
CVE-2019-19496 | 1 Alfresco | 1 Alfresco | 2019-12-11 | 3.5 LOW | 5.4 MEDIUM |
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document. | |||||
CVE-2019-19708 | 1 Mediawiki | 1 Visual Editor | 2019-12-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute. | |||||
CVE-2017-3151 | 1 Apache | 1 Atlas | 2019-12-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. | |||||
CVE-2019-19551 | 1 Sangoma | 1 Freepbx | 2019-12-11 | 3.5 LOW | 4.8 MEDIUM |
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values in some of the time/date formatting and time-zone fields. These fields are not being properly sanitized. If this is done and a user (such as an admin) visits the User Management screen and views that user's profile, the XSS payload will render and execute in the context of the victim user's account. |