Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-5403 1 Hp 1 3par Storeserv Management Console 2019-08-16 3.5 LOW 4.8 MEDIUM
A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
CVE-2017-18505 1 Bestwebsoft 1 Twitter Button 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The twitter-plugin plugin before 2.55 for WordPress has XSS.
CVE-2019-14770 1 Backdropcms 1 Backdrop Core 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such as by creating a content type or layout. Such permissions are usually restricted to trusted or administrative users.)
CVE-2019-5398 1 Hp 2 3par Service Processor, 3par Service Processor Firmware 2019-08-16 3.5 LOW 5.4 MEDIUM
A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
CVE-2017-18493 1 Bestwebsoft 1 Custom Admin Page 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
CVE-2012-6713 1 Wp-jobmanager 1 Job Manager 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
CVE-2015-9296 1 Never5 1 Download Monitor 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
CVE-2017-18492 1 Bestwebsoft 1 Contact Form To Db 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
CVE-2015-9293 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
CVE-2013-7475 1 Bestwebsoft 1 Contact Form 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
CVE-2015-9294 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
CVE-2015-9295 1 Bestwebsoft 1 Contact Form 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
CVE-2015-9300 1 Wp-events-plugin 1 Events Manager 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
CVE-2015-9299 1 Wp-events-plugin 1 Events Manager 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2016-10868 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
CVE-2016-10869 1 Bestwebsoft 1 Contact Form 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
CVE-2016-10870 1 Gtranslate 1 Google Language Translator 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The google-language-translator plugin before 5.0.06 for WordPress has XSS.
CVE-2016-10871 1 Ibericode 1 Mailchimp 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
CVE-2017-18489 1 Mediaburst 1 Contact Form 7 - Clockwork Sms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
CVE-2017-18490 1 Bestwebsoft 1 Contact Form Multi 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.