Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-18228 | 1 Bmc | 1 Remedy Action Request System | 2018-04-09 | 3.5 LOW | 5.4 MEDIUM |
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request. | |||||
CVE-2018-7707 | 1 Securenvoy | 1 Securmail | 2018-04-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message. | |||||
CVE-2018-7703 | 1 Securenvoy | 1 Securmail | 2018-04-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmail/getmessage.exe. | |||||
CVE-2018-8722 | 1 Zohocorp | 1 Manageengine Desktop Central | 2018-04-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. | |||||
CVE-2018-8721 | 1 Zohocorp | 1 Manageengine Eventlog Analyzer | 2018-04-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen | |||||
CVE-2018-1000084 | 1 Wolfcms | 1 Wolf Cms | 2018-04-06 | 3.5 LOW | 5.4 MEDIUM |
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout Name . | |||||
CVE-2018-1000108 | 1 Jenkins | 1 Cppncss | 2018-04-04 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed. | |||||
CVE-2018-1000113 | 1 Jenkins | 1 Testlink | 2018-04-04 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript | |||||
CVE-2018-6226 | 1 Trendmicro | 1 Email Encryption Gateway | 2018-04-04 | 3.5 LOW | 5.4 MEDIUM |
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems. | |||||
CVE-2018-6227 | 1 Trendmicro | 1 Email Encryption Gateway | 2018-04-04 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems. | |||||
CVE-2018-8069 | 1 Qcms | 1 Qcms | 2018-03-30 | 3.5 LOW | 5.4 MEDIUM |
QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI. | |||||
CVE-2018-8070 | 1 Qcms | 1 Qcms | 2018-03-30 | 3.5 LOW | 5.4 MEDIUM |
QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI. | |||||
CVE-2017-2147 | 1 Wp-statistics | 1 Wp Statistics | 2018-03-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2017-1000425 | 1 Liferay | 1 Liferay Portal | 2018-03-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter. | |||||
CVE-2018-7893 | 1 Cmsmadesimple | 1 Cms Made Simple | 2018-03-29 | 3.5 LOW | 4.8 MEDIUM |
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter. | |||||
CVE-2018-8058 | 1 Cmsmadesimple | 1 Cms Made Simple | 2018-03-29 | 3.5 LOW | 4.8 MEDIUM |
CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter. | |||||
CVE-2018-8078 | 1 Yzmcms | 1 Yzmcms | 2018-03-29 | 3.5 LOW | 5.4 MEDIUM |
YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html. | |||||
CVE-2018-0547 | 1 Soflyy | 1 Wp All Import | 2018-03-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-0546 | 1 Soflyy | 1 Wp All Import | 2018-03-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-6527 | 1 D-link | 6 Dir-860l, Dir-860l Firmware, Dir-865l and 3 more | 2018-03-27 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted deviceid parameter to soap.cgi. |