Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17001 1 Ricoh 2 Sp 4510sf, Sp 4510sf Firmware 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-17322 1 Yunucms 1 Yunucms 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
CVE-2018-17003 1 Limesurvey 1 Limesurvey 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
CVE-2018-16965 1 Zohocorp 1 Manageengine Supportcenter Plus 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
CVE-2018-16833 1 Zohocorp 1 Manageengine Desktop Central 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
CVE-2018-16346 1 Chemcms Project 1 Chemcms 2018-11-09 3.5 LOW 4.8 MEDIUM
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
CVE-2018-9282 1 Subsonic 1 Subsonic 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.view; no administrator access is required. By injecting a JavaScript payload, this flaw could be used to manipulate a user's session, or elevate privileges by targeting an administrative user.
CVE-2018-11352 1 Wallabag 1 Wallabag 2018-11-09 2.1 LOW 4.0 MEDIUM
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.
CVE-2018-2464 1 Sap 1 Netweaver 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
CVE-2018-16955 1 Oracle 1 Webcenter Interaction 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// scheme, is unsafely reflected in a HTML META tag in the HTTP response. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
CVE-2018-16953 1 Oracle 1 Webcenter Interaction 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User input from the name parameter is unsafely reflected in the server response. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
CVE-2018-16327 1 Intelliants 1 Subrion 2018-11-09 3.5 LOW 4.8 MEDIUM
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
CVE-2018-17140 1 Vms-studio 1 Quizlord 2018-11-09 3.5 LOW 5.4 MEDIUM
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
CVE-2018-17113 1 Easycms 1 Easycms 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
CVE-2018-16316 1 Portainer 1 Portainer 2018-11-09 3.5 LOW 5.4 MEDIUM
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.
CVE-2018-17077 1 Yiqicms Project 1 Yiqicms 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed.
CVE-2018-10763 1 Synametrics 1 Synaman 2018-11-09 3.5 LOW 4.8 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page.
CVE-2018-17051 1 Knet 1 Cisco Configuration Manager 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
CVE-2018-17044 1 Yzmcms 1 Yzmcms 2018-11-09 3.5 LOW 4.8 MEDIUM
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
CVE-2018-17049 1 Cqu Lankers Project 1 Cqu Lankers 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.