Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-20583 | 1 Thephpleague | 1 Commonmark | 2019-01-15 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt). | |||||
CVE-2018-20594 | 1 Hsweb | 1 Hsweb | 2019-01-15 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java. | |||||
CVE-2018-20368 | 1 Averta | 1 Master Slider | 2019-01-15 | 3.5 LOW | 5.4 MEDIUM |
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback. | |||||
CVE-2018-20369 | 1 Barracuda | 1 Message Archiver | 2019-01-15 | 4.3 MEDIUM | 6.1 MEDIUM |
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module. | |||||
CVE-2016-10736 | 1 Devpups | 1 Social Pug | 2019-01-15 | 4.3 MEDIUM | 6.1 MEDIUM |
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter. | |||||
CVE-2018-1000826 | 1 Microweber | 1 Microweber | 2019-01-15 | 4.3 MEDIUM | 6.1 MEDIUM |
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code. | |||||
CVE-2019-0558 | 1 Microsoft | 2 Business Productivity Servers, Sharepoint Server | 2019-01-15 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557. | |||||
CVE-2019-0556 | 1 Microsoft | 1 Sharepoint Server | 2019-01-15 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0557, CVE-2019-0558. | |||||
CVE-2019-0557 | 1 Microsoft | 1 Sharepoint Server | 2019-01-15 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0556, CVE-2019-0558. | |||||
CVE-2018-14481 | 1 Osclass | 1 Osclass | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280. | |||||
CVE-2018-18005 | 1 Vivotek | 1 Camera | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter. | |||||
CVE-2018-18244 | 1 Vivotek | 1 Camera | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header. | |||||
CVE-2018-19799 | 1 Dolibarr | 1 Dolibarr | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. | |||||
CVE-2018-16165 | 1 Jpcert | 1 Logontracer | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-20486 | 1 Metinfo | 1 Metinfo | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter. | |||||
CVE-2018-19414 | 1 Plikli | 1 Plikli Cms | 2019-01-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to groups.php; (2) username parameter to login.php; or (3) date parameter to search.php. | |||||
CVE-2018-20379 | 1 Technicolor | 2 Dpc3928sl, Dpc3928sl Firmware | 2019-01-14 | 2.6 LOW | 4.7 MEDIUM |
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001. | |||||
CVE-2018-20373 | 1 Tendacn | 2 Adsl, Adsl Firmware | 2019-01-14 | 3.5 LOW | 5.4 MEDIUM |
Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client. | |||||
CVE-2018-16173 | 1 Thimpress | 1 Learnpress | 2019-01-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-19924 | 1 Sales \& Company Management System Project | 1 Sales \& Company Management System | 2019-01-11 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address. |