Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-3961 | 1 Tenable | 1 Nessus | 2019-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a users browser session. | |||||
CVE-2019-12949 | 1 Netgate | 1 Pfsense | 2019-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server. | |||||
CVE-2015-4413 | 1 Nextendweb | 1 Facebook Connect | 2019-06-25 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. | |||||
CVE-2019-12964 | 1 Livezilla | 1 Livezilla | 2019-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject. | |||||
CVE-2015-3904 | 1 Roomcloud | 1 Roomcloud | 2019-06-25 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) pin, (2) start_day, (3) start_month, (4) start_year, (5) end_day, (6) end_month, (7) end_year, (8) lang, (9) adults, or (10) children parameter. | |||||
CVE-2019-12963 | 1 Livezilla | 1 Livezilla | 2019-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action. | |||||
CVE-2015-5460 | 1 Snorby Project | 1 Snorby | 2019-06-25 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification. | |||||
CVE-2019-12935 | 1 Shopware | 1 Shopware | 2019-06-24 | 4.3 MEDIUM | 6.1 MEDIUM |
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. | |||||
CVE-2019-12745 | 1 Seeddms | 1 Seeddms | 2019-06-24 | 3.5 LOW | 5.4 MEDIUM |
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. | |||||
CVE-2019-12801 | 1 Seeddms | 1 Seeddms | 2019-06-24 | 4.3 MEDIUM | 6.1 MEDIUM |
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. | |||||
CVE-2015-6808 | 1 Getlevelten | 1 Spotlight | 2019-06-24 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the Spotlight module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title. | |||||
CVE-2018-17146 | 1 Nagios | 1 Nagios Xi | 2019-06-23 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page. | |||||
CVE-2018-16249 | 1 B3log | 1 Symphony | 2019-06-21 | 3.5 LOW | 4.8 MEDIUM |
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web site name. | |||||
CVE-2018-16250 | 1 Creatiwity | 1 Witycms | 2019-06-21 | 3.5 LOW | 5.4 MEDIUM |
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name" parameters. | |||||
CVE-2018-16514 | 1 Mantisbt | 1 Mantisbt | 2019-06-21 | 2.6 LOW | 4.7 MEDIUM |
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055. | |||||
CVE-2017-8332 | 1 Securifi | 6 Almond, Almond\+, Almond\+firmware and 3 more | 2019-06-21 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from watching content that might be deemed unsafe using the web management interface. It seems that the device does not implement any cross-site scripting protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a stored cross-site scripting payload on the user's browser and execute any action on the device provided by the web management interface. | |||||
CVE-2017-14395 | 1 Forgerock | 2 Access Management, Openam | 2019-06-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS. | |||||
CVE-2018-16248 | 1 B3log | 1 Solo | 2019-06-21 | 4.3 MEDIUM | 6.1 MEDIUM |
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a carefully crafted site name in an admin-authenticated HTTP request. | |||||
CVE-2018-16247 | 1 Yzmcms | 1 Yzmcms | 2019-06-20 | 3.5 LOW | 5.4 MEDIUM |
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter. | |||||
CVE-2017-9390 | 1 Getvera | 4 Veraedge, Veraedge Firmware, Veralite and 1 more | 2019-06-20 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called connect.sh which is supposed to return a specific cookie for the user when the user is authenticated to https://home.getvera.com. One of the parameters retrieved by this script is "RedirectURL". However, the application lacks strict input validation of this parameter and this allows an attacker to execute the client-side code on this application. |