Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-10567 | 1 Flexense | 1 Vx Search | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Flexense VX Search Enterprise from v10.1.12 to v10.7. | |||||
CVE-2018-10565 | 1 Flexense | 1 Disksavvy | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Flexense DiskSavvy Enterprise from v10.4 to v10.7. | |||||
CVE-2018-10566 | 1 Flexense | 1 Dupscout | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7. | |||||
CVE-2018-10563 | 1 Flexense | 1 Syncbreeze | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS in Flexense SyncBreeze affects all versions (tested from SyncBreeze Enterprise from v10.1 to v10.7). | |||||
CVE-2018-10564 | 1 Flexense | 1 Diskpulse | 2018-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Flexense DiskPulse Enterprise from v10.4 to v10.7. | |||||
CVE-2011-3841 | 1 Wpsymposiumpro | 1 Wp Symposium | 2018-06-04 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter. | |||||
CVE-2014-3110 | 1 Honeywell | 2 Falcon Xlweb Linux Controller, Falcon Xlweb Xlwebexe | 2018-05-26 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input. | |||||
CVE-2018-1473 | 1 Ibm | 1 Bigfix Platform | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691. | |||||
CVE-2018-1363 | 1 Ibm | 1 Jazz Reporting Service | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448. | |||||
CVE-2017-1750 | 1 Ibm | 1 Jazz Reporting Service | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523. | |||||
CVE-2017-13073 | 1 Qnap | 1 Photo Station | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2018-10268 | 1 Fastadmin | 1 Fastadmin | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter. | |||||
CVE-2018-6518 | 1 Compo | 1 Composr Cms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php. | |||||
CVE-2018-10329 | 1 Phpipam | 1 Phpipam | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. | |||||
CVE-2017-1724 | 1 Ibm | 5 Qradar Incident Forensics, Qradar Network Insights, Qradar Risk Manager and 2 more | 2018-05-25 | 3.5 LOW | 6.1 MEDIUM |
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814. | |||||
CVE-2018-10366 | 1 User Project | 1 User | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field. | |||||
CVE-2018-10422 | 1 Hongcms Project | 1 Hongcms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field. | |||||
CVE-2017-14740 | 1 Genixcms | 1 Genixcms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu. | |||||
CVE-2014-2908 | 1 Siemens | 6 Simatic S7 Cpu-1211c, Simatic S7 Cpu 1200 Firmware, Simatic S7 Cpu 1212c and 3 more | 2018-05-24 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-10368 | 1 Wuzhicms | 1 Wuzhi Cms | 2018-05-24 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement. |