Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-7418 | 1 Samsung | 3 Syncthru Web Service, X7400gx, X7400gx Firmware | 2019-03-25 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc. | |||||
CVE-2019-7420 | 1 Samsung | 3 Syncthru Web Service, X7400gx, X7400gx Firmware | 2019-03-25 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.application/information/networkinformationView.sws" in the tabName parameter. | |||||
CVE-2019-7437 | 1 Opensource Classified Ads Script Project | 1 Opensource Classified Ads Script | 2019-03-25 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field. | |||||
CVE-2018-20736 | 1 Wso2 | 1 Api Manager | 2019-03-25 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product. | |||||
CVE-2018-20737 | 1 Wso2 | 3 Api Manager, Identity Server, Identity Server As Key Manager | 2019-03-25 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. | |||||
CVE-2018-19694 | 1 Hms-networks | 16 Netbiter Ec150, Netbiter Ec150 Firmware, Netbiter Ec250 and 13 more | 2019-03-25 | 4.3 MEDIUM | 6.1 MEDIUM |
HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. | |||||
CVE-2007-1358 | 1 Apache | 1 Tomcat | 2019-03-25 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616". | |||||
CVE-2007-2450 | 1 Apache | 1 Tomcat | 2019-03-25 | 3.5 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors. | |||||
CVE-2019-9912 | 1 Wpgmaps | 1 Wp Google Maps | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO. | |||||
CVE-2019-9913 | 1 Wp-livechat | 1 Wp Live Chat Support | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS. | |||||
CVE-2019-9925 | 1 S-cms | 1 S-cms | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter. | |||||
CVE-2019-7416 | 1 Opentext | 1 Documentum Webtop | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable. | |||||
CVE-2018-14486 | 1 Dnnsoftware | 1 Dotnetnuke | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. | |||||
CVE-2018-17997 | 1 Layerbb | 1 Layerbb | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | |||||
CVE-2019-7424 | 1 Zohocorp | 1 Manageengine Netflow Analyzer | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903. | |||||
CVE-2019-7423 | 1 Zohocorp | 1 Manageengine Netflow Analyzer | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter. | |||||
CVE-2019-7422 | 1 Zohocorp | 1 Manageengine Netflow Analyzer | 2019-03-22 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter. | |||||
CVE-2017-7059 | 1 Apple | 3 Iphone Os, Safari, Tvos | 2019-03-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. | |||||
CVE-2017-2504 | 1 Apple | 3 Iphone Os, Safari, Tvos | 2019-03-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands. | |||||
CVE-2018-20141 | 1 Abantecart | 1 Abantecart | 2019-03-21 | 4.3 MEDIUM | 6.1 MEDIUM |
AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring. |