Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1933 1 Ibm 1 Planning Analytics 2019-05-08 3.5 LOW 5.4 MEDIUM
IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153177.
CVE-2019-11813 1 Misp 1 Misp 2019-05-08 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.
CVE-2019-11812 1 Misp 1 Misp 2019-05-08 4.3 MEDIUM 6.1 MEDIUM
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.
CVE-2019-7426 1 Zohocorp 1 Manageengine Netflow Analyzer 2019-05-08 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
CVE-2019-7427 1 Zohocorp 1 Manageengine Netflow Analyzer 2019-05-08 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
CVE-2019-7541 1 Rukovoditel 1 Rukovoditel 2019-05-08 4.3 MEDIUM 6.1 MEDIUM
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
CVE-2018-20503 1 Alliedtelesis 2 8100l\/8, 8100l\/8 Firmware 2019-05-08 4.3 MEDIUM 6.1 MEDIUM
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
CVE-2018-4065 1 Sierrawireless 2 Airlink Es450, Airlink Es450 Firmware 2019-05-07 4.3 MEDIUM 6.1 MEDIUM
An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the execution of javascript code running on the victim's browser. An attacker can get a victim to click a link, or embedded URL, that redirects to the reflected cross-site scripting vulnerability to trigger this vulnerability.
CVE-2018-14478 1 Coppermine-gallery 1 Coppermine Photo Gallery 2019-05-07 4.3 MEDIUM 6.1 MEDIUM
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
CVE-2019-11629 1 Sonatype 1 Nexus Repository Manager 2019-05-07 4.3 MEDIUM 6.1 MEDIUM
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
CVE-2019-11537 1 Osticket 1 Osticket 2019-05-07 4.3 MEDIUM 6.1 MEDIUM
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion.
CVE-2019-9709 1 Mahara 1 Mahara 2019-05-07 3.5 LOW 5.4 MEDIUM
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user.
CVE-2019-1838 1 Cisco 1 Application Policy Infrastructure Controller 2019-05-07 3.5 LOW 5.4 MEDIUM
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. This vulnerability has been fixed in software version 14.1(1i).
CVE-2018-13983 1 Impresscms 1 Impresscms 2019-05-07 4.3 MEDIUM 6.1 MEDIUM
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.
CVE-2017-1457 1 Ibm 1 Qradar Network Security 2019-05-06 4.3 MEDIUM 6.1 MEDIUM
IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128376.
CVE-2019-10261 1 Centos-webpanel 1 Centos Web Panel 2019-05-06 3.5 LOW 4.8 MEDIUM
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.
CVE-2019-11504 1 Zotonic 1 Zotonic 2019-05-06 3.5 LOW 4.8 MEDIUM
Zotonic before version 0.47 has mod_admin XSS.
CVE-2019-3490 1 Microfocus 1 Open Enterprise Server 2019-05-06 4.3 MEDIUM 6.1 MEDIUM
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.
CVE-2019-10864 1 Veronalabs 1 Wp Statistics 2019-05-06 4.3 MEDIUM 6.1 MEDIUM
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
CVE-2019-1856 1 Cisco 1 Prime Collaboration Assurance 2019-05-06 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance (PCA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to the insufficient validation of data supplied by external devices to the web-based management interface of an affected PCA device. An attacker in control of devices integrated with an affected PCA device could exploit this vulnerability by using crafted data in certain fields of the controlled devices. A successful exploit could allow the attacker to execute arbitrary script code in the context of the PCA web-based management interface or allow the attacker to access sensitive browser-based information.