Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-1000095 | 1 Redhat | 1 Ovirt-engine | 2019-11-06 | 3.5 LOW | 4.8 MEDIUM |
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3. | |||||
CVE-2019-13066 | 1 Sahipro | 1 Sahi Pro | 2019-11-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS. | |||||
CVE-2019-8117 | 1 Magento | 1 Magento | 2019-11-06 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticates user can inject arbitrary JavaScript code via product view id specification. | |||||
CVE-2019-8115 | 1 Magento | 1 Magento | 2019-11-06 | 3.5 LOW | 4.8 MEDIUM |
A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can inject arbitrary JavaScript code when adding an image for during simple product creation. | |||||
CVE-2019-8120 | 1 Magento | 1 Magento | 2019-11-06 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated user can inject arbitrary Javascript code by manipulating section of a POST request related to customer's email address. | |||||
CVE-2019-18207 | 1 Zucchetti | 1 Infobusiness | 2019-11-06 | 3.5 LOW | 5.4 MEDIUM |
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page. | |||||
CVE-2014-3649 | 1 Redhat | 1 Jboss Aerogear | 2019-11-06 | 4.3 MEDIUM | 6.1 MEDIUM |
JBoss AeroGear has reflected XSS via the password field | |||||
CVE-2019-18653 | 2 Avast, Microsoft | 2 Antivirus, Windows | 2019-11-06 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. | |||||
CVE-2013-1932 | 1 Mantisbt | 1 Mantisbt | 2019-11-06 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name. | |||||
CVE-2019-6657 | 1 F5 | 13 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 10 more | 2019-11-05 | 4.3 MEDIUM | 6.1 MEDIUM |
On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility. | |||||
CVE-2010-3660 | 1 Typo3 | 1 Typo3 | 2019-11-05 | 3.5 LOW | 5.4 MEDIUM |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend. | |||||
CVE-2013-4107 | 1 Cryptocat Project | 1 Cryptocat | 2019-11-05 | 4.3 MEDIUM | 6.1 MEDIUM |
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting | |||||
CVE-2010-3665 | 1 Typo3 | 1 Typo3 | 2019-11-05 | 3.5 LOW | 5.4 MEDIUM |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager. | |||||
CVE-2005-2350 | 1 Websieve Project | 1 Websieve | 2019-11-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface. | |||||
CVE-2019-18654 | 2 Avg, Microsoft | 2 Anti-virus, Windows | 2019-11-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. | |||||
CVE-2019-18636 | 1 Jitbit | 1 .net Forum | 2019-11-04 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter. | |||||
CVE-2019-18664 | 1 Secudos | 1 Domos | 2019-11-04 | 3.5 LOW | 5.4 MEDIUM |
The Log module in SECUDOS DOMOS before 5.6 allows XSS. | |||||
CVE-2013-1934 | 2 Debian, Mantisbt | 2 Debian Linux, Mantisbt | 2019-11-01 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value. | |||||
CVE-2018-18678 | 1 Gnuboard | 1 Gnuboard5 | 2019-11-01 | 4.3 MEDIUM | 6.1 MEDIUM |
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter. | |||||
CVE-2019-18205 | 1 Zucchetti | 1 Infobusiness | 2019-11-01 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter. |