Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-14890 | 1 Vectra | 1 Cognito | 2018-11-07 | 3.5 LOW | 5.4 MEDIUM |
Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console. | |||||
CVE-2018-1000665 | 1 Dojotoolkit | 1 Dojo | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14. | |||||
CVE-2018-17321 | 1 Seacms | 1 Seacms | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action. | |||||
CVE-2018-7795 | 1 Schneider-electric | 2 Powerlogic Pm5560, Powerlogic Pm5560 Firmware | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code. | |||||
CVE-2018-17031 | 1 Gogs | 1 Gogs | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent. | |||||
CVE-2017-15429 | 3 Debian, Google, Redhat | 5 Debian Linux, Chrome, Enterprise Linux Desktop and 2 more | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. | |||||
CVE-2018-1000670 | 1 Koha | 1 Koha | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability in Multiple fields on multiple pages including /cgi-bin/koha/acqui/supplier.pl?op=enter , /cgi-bin/koha/circ/circulation.pl?borrowernumber=[number] , /cgi-bin/koha/serials/subscription-add.pl that can result in Privilege escalation by taking control of higher privileged users browser sessions. This attack appear to be exploitable via Victims must be socially engineered to visit a vulnerable webpage containing malicious payload. This vulnerability appears to have been fixed in 17.11. | |||||
CVE-2018-17021 | 1 Asus | 2 Gt-ac5300, Gt-ac5300 Firmware | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter. | |||||
CVE-2018-17034 | 1 Ucms Project | 1 Ucms | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter. | |||||
CVE-2018-17061 | 1 Bullguard | 1 Safe Browsing | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results. | |||||
CVE-2018-17062 | 1 Seacms | 1 Seacms | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter. | |||||
CVE-2018-17085 | 1 Otcms | 1 Otcms | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr. | |||||
CVE-2018-17086 | 1 Otcms | 1 Otcms | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName. | |||||
CVE-2018-17128 | 1 Mybb | 1 Mybb | 2018-11-07 | 3.5 LOW | 5.4 MEDIUM |
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | |||||
CVE-2018-16607 | 1 Opmantek | 1 Open-audit | 2018-11-07 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field. | |||||
CVE-2018-16759 | 1 Easycms | 1 Easycms | 2018-11-07 | 4.3 MEDIUM | 6.1 MEDIUM |
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event. | |||||
CVE-2018-16736 | 1 Rcfilters Project | 1 Rcfilters | 2018-11-06 | 3.5 LOW | 5.4 MEDIUM |
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings). | |||||
CVE-2018-16363 | 1 Webdesi9 | 1 File Manager | 2018-11-06 | 3.5 LOW | 5.4 MEDIUM |
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php. | |||||
CVE-2018-16324 | 1 Icewarp | 1 Mail Server | 2018-11-06 | 4.3 MEDIUM | 6.1 MEDIUM |
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. | |||||
CVE-2018-15574 | 1 Reprisesoftware | 1 Reprise License Manager | 2018-11-06 | 4.3 MEDIUM | 6.1 MEDIUM |
** DISPUTED ** An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability." |