Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-11511 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2019-06-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. | |||||
CVE-2016-10245 | 1 Doxygen | 1 Doxygen | 2019-06-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection. | |||||
CVE-2019-10047 | 1 Pydio | 1 Pydio | 2019-06-03 | 3.5 LOW | 5.4 MEDIUM |
A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML file containing JavaScript code and afterwards a file preview URL can be used to access the uploaded file. If a malicious user shares an uploaded HTML file containing JavaScript code with another user of the application, and tricks an authenticated victim into accessing a URL that results in the HTML code being interpreted by the web browser, then the included JavaScript code is executed under the context of the victim user session. | |||||
CVE-2019-10325 | 1 Jenkins | 1 Warnings Next Generation | 2019-06-03 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages. | |||||
CVE-2019-12566 | 1 Veronalabs | 1 Wp Statistics | 2019-06-03 | 3.5 LOW | 5.4 MEDIUM |
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user. | |||||
CVE-2019-4137 | 1 Ibm | 1 Spectrum Control | 2019-06-03 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158333. | |||||
CVE-2013-5072 | 1 Microsoft | 1 Exchange Server | 2019-05-31 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability." | |||||
CVE-2019-12507 | 1 Phprelativepath Project | 1 Phprelativepath | 2019-05-31 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS vulnerability exists in PHPRelativePath (aka Relative Path) through 1.0.2 via the RelativePath.Example1.php path parameter. | |||||
CVE-2015-7609 | 1 Synacor | 1 Zimbra Collaboration Suite | 2019-05-31 | 4.3 MEDIUM | 6.1 MEDIUM |
Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra. | |||||
CVE-2019-4184 | 1 Ibm | 1 Jazz Reporting Service | 2019-05-31 | 3.5 LOW | 5.4 MEDIUM |
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974. | |||||
CVE-2018-10948 | 1 Synacor | 1 Zimbra Collaboration Suite | 2019-05-31 | 3.5 LOW | 4.8 MEDIUM |
Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs. | |||||
CVE-2018-14425 | 1 Synacor | 1 Zimbra Collaboration Suite | 2019-05-31 | 4.3 MEDIUM | 6.1 MEDIUM |
There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1. | |||||
CVE-2018-18631 | 1 Synacor | 1 Zimbra Collaboration Suite | 2019-05-30 | 4.3 MEDIUM | 6.1 MEDIUM |
mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS. | |||||
CVE-2018-14013 | 1 Synacor | 1 Zimbra Collaboration Suite | 2019-05-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. | |||||
CVE-2018-13375 | 1 Fortinet | 2 Fortianalyzer, Fortimanager | 2019-05-30 | 4.3 MEDIUM | 6.1 MEDIUM |
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature enabled). | |||||
CVE-2019-12347 | 1 Netgate | 1 Pfsense | 2019-05-30 | 4.3 MEDIUM | 6.1 MEDIUM |
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors. | |||||
CVE-2016-5760 | 1 Novell | 1 Groupwise | 2019-05-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp. | |||||
CVE-2015-6508 | 1 Netgate | 1 Pfsense | 2019-05-30 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the descr parameter in a "new" action to system_authservers.php. | |||||
CVE-2014-4693 | 2 Netgate, Pfsense | 2 Pfsense, Snort Package | 2019-05-30 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the eng parameter to snort_import_aliases.php or (2) unspecified variables to snort_select_alias.php. | |||||
CVE-2015-6511 | 1 Netgate | 1 Pfsense | 2019-05-30 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the server[] parameter to services_ntpd.php. |