Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-5049 | 2 Debian, Mortbay | 2 Debian Linux, Jetty | 2019-11-08 | 4.3 MEDIUM | 6.1 MEDIUM |
WebApp JSP Snoop page XSS in jetty though 6.1.21. | |||||
CVE-2011-4629 | 1 Typo3 | 1 Typo3 | 2019-11-08 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the admin panel. | |||||
CVE-2011-4630 | 1 Typo3 | 1 Typo3 | 2019-11-08 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browse_links wizard. | |||||
CVE-2016-1000037 | 2 Fedoraproject, Redhat | 3 Fedora, Enterprise Linux, Pagure | 2019-11-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Pagure: XSS possible in file attachment endpoint | |||||
CVE-2011-4631 | 1 Typo3 | 1 Typo3 | 2019-11-08 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler. | |||||
CVE-2011-1133 | 1 S9y | 1 Serendipity | 2019-11-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php. | |||||
CVE-2011-1135 | 1 S9y | 1 Serendipity | 2019-11-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php. | |||||
CVE-2011-4626 | 1 Typo3 | 1 Typo3 | 2019-11-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function. | |||||
CVE-2011-4632 | 1 Typo3 | 1 Typo3 | 2019-11-08 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message. | |||||
CVE-2019-8233 | 1 Magento | 1 Magento | 2019-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
In Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1, an unauthenticated user can inject arbitrary JavaScript code as a result of the sanitization engine ignoring HTML comments. | |||||
CVE-2009-5048 | 1 Mortbay | 1 Jetty | 2019-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20. | |||||
CVE-2019-16873 | 1 Portainer | 1 Portainer | 2019-11-07 | 3.5 LOW | 5.4 MEDIUM |
Portainer before 1.22.1 has XSS (issue 1 of 2). | |||||
CVE-2019-16878 | 1 Portainer | 1 Portainer | 2019-11-07 | 3.5 LOW | 5.4 MEDIUM |
Portainer before 1.22.1 has XSS (issue 2 of 2). | |||||
CVE-2019-13080 | 1 Quest | 1 Kace Systems Management Appliance | 2019-11-07 | 3.5 LOW | 5.4 MEDIUM |
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an administrator's browser. | |||||
CVE-2019-13077 | 1 Quest | 1 Kace Systems Management Appliance | 2019-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows an attacker to create a malicious link in order to attack authenticated users. | |||||
CVE-2019-12917 | 1 Quest | 1 Kace Systems Management Appliance | 2019-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO. | |||||
CVE-2011-4903 | 1 Typo3 | 1 Typo3 | 2019-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function. | |||||
CVE-2019-13081 | 1 Quest | 1 Kace Systems Management Appliance | 2019-11-07 | 3.5 LOW | 5.4 MEDIUM |
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows an authenticated user to execute arbitrary JavaScript in a service desk user's browser. | |||||
CVE-2019-8228 | 1 Magento | 1 Magento | 2019-11-07 | 3.5 LOW | 4.8 MEDIUM |
in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creating a new email template or editing existing email template. | |||||
CVE-2019-17551 | 1 Apakgroup | 1 Wholesale Floorplanning Finance | 2019-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected. |