Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-8608 | 1 Microsoft | 1 Dynamics 365 | 2018-12-14 | 3.5 LOW | 5.4 MEDIUM |
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8607. | |||||
CVE-2018-8547 | 1 Microsoft | 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more | 2018-12-14 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. | |||||
CVE-2018-19195 | 1 Xiaocms | 1 Xiaocms | 2018-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file. | |||||
CVE-2018-19170 | 1 Jpress | 1 Jpress | 2018-12-13 | 3.5 LOW | 4.8 MEDIUM |
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter. | |||||
CVE-2018-19193 | 1 Xiaocms | 1 Xiaocms | 2018-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen. | |||||
CVE-2018-19080 | 2 Foscam, Opticam | 6 C2, C2 Application Firmware, C2 System Firmware and 3 more | 2018-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS. | |||||
CVE-2018-19178 | 1 Jeesns | 1 Jeesns | 2018-12-13 | 3.5 LOW | 5.4 MEDIUM |
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886. | |||||
CVE-2018-19092 | 1 Yzmcms | 1 Yzmcms | 2018-12-13 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie. | |||||
CVE-2018-17184 | 1 Apache | 1 Syncope | 2018-12-13 | 3.5 LOW | 5.4 MEDIUM |
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed. | |||||
CVE-2018-10586 | 1 Netgain-systems | 1 Enterprise Manager | 2018-12-12 | 3.5 LOW | 4.8 MEDIUM |
NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions before 10.1.12. | |||||
CVE-2018-19141 | 2 Debian, Otrs | 2 Debian Linux, Open Ticket Request System | 2018-12-12 | 3.5 LOW | 4.8 MEDIUM |
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled. | |||||
CVE-2018-19142 | 1 Otrs | 1 Open Ticket Request System | 2018-12-12 | 3.5 LOW | 4.8 MEDIUM |
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL. | |||||
CVE-2018-15707 | 1 Advantech | 1 Webaccess | 2018-12-12 | 3.5 LOW | 5.4 MEDIUM |
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things. | |||||
CVE-2018-19056 | 1 Ipandao | 1 Editor.md | 2018-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. | |||||
CVE-2018-19057 | 1 Sparksuite | 1 Simplemde | 2018-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element. | |||||
CVE-2018-18775 | 1 Microstrategy | 1 Microstrategy Web | 2018-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product. | |||||
CVE-2018-18776 | 1 Microstrategy | 1 Microstrategy Web | 2018-12-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product. | |||||
CVE-2018-19131 | 1 Squid-cache | 1 Squid | 2018-12-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. | |||||
CVE-2018-19136 | 1 Domainmod | 1 Domainmod | 2018-12-11 | 4.3 MEDIUM | 6.1 MEDIUM |
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. | |||||
CVE-2018-19137 | 1 Domainmod | 1 Domainmod | 2018-12-11 | 4.3 MEDIUM | 6.1 MEDIUM |
DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter. |