Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-3618 | 1 Nagios | 1 Business Process Intelligence | 2018-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php. | |||||
CVE-2015-3619 | 1 Virtuemart | 1 Virtuemart | 2018-02-26 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company." | |||||
CVE-2018-6291 | 1 Kaspersky | 1 Secure Mail Gateway | 2018-02-23 | 4.3 MEDIUM | 6.1 MEDIUM |
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1. | |||||
CVE-2017-5124 | 2 Debian, Google | 2 Debian Linux, Chrome | 2018-02-23 | 4.3 MEDIUM | 6.1 MEDIUM |
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page. | |||||
CVE-2017-8783 | 1 Synacor | 1 Zimbra Collaboration Suite | 2018-02-23 | 3.5 LOW | 5.4 MEDIUM |
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS. | |||||
CVE-2017-17703 | 1 Synacor | 1 Zimbra Collaboration Suite | 2018-02-23 | 4.3 MEDIUM | 6.1 MEDIUM |
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS. | |||||
CVE-2013-6459 | 1 Mislav Marohnic | 1 Will Paginate | 2018-02-22 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links. | |||||
CVE-2018-6355 | 1 Iball | 2 Ib-wrb302n, Ib-wrb302n Firmware | 2018-02-21 | 4.3 MEDIUM | 6.1 MEDIUM |
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter. | |||||
CVE-2016-4318 | 1 Atlassian | 1 Jira | 2018-02-15 | 3.5 LOW | 4.8 MEDIUM |
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. | |||||
CVE-2016-4317 | 1 Atlassian | 1 Confluence | 2018-02-15 | 3.5 LOW | 5.4 MEDIUM |
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. | |||||
CVE-2018-6354 | 1 Formspree | 1 Formspree | 2018-02-15 | 4.3 MEDIUM | 6.1 MEDIUM |
templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter. | |||||
CVE-2018-6465 | 1 Wp-property-hive | 1 Propertyhive | 2018-02-15 | 4.3 MEDIUM | 6.1 MEDIUM |
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php. | |||||
CVE-2017-18083 | 1 Atlassian | 1 Confluence | 2018-02-15 | 3.5 LOW | 5.4 MEDIUM |
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. | |||||
CVE-2018-6561 | 1 Dojotoolkit | 1 Dojo | 2018-02-15 | 4.3 MEDIUM | 6.1 MEDIUM |
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. | |||||
CVE-2016-0303 | 1 Ibm | 1 Tivoli Integrated Portal | 2018-02-15 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-6194 | 1 Splashing Images Project | 1 Splashing Images | 2018-02-14 | 3.5 LOW | 4.8 MEDIUM |
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search parameter to wp-admin/upload.php. | |||||
CVE-2016-0311 | 1 Ibm | 1 Tivoli Business Service Manager | 2018-02-14 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480. | |||||
CVE-2018-0508 | 1 Kkcald Project | 1 Kkcald | 2018-02-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-6550 | 1 Monstra | 1 Monstra | 2018-02-14 | 3.5 LOW | 5.4 MEDIUM |
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php. | |||||
CVE-2018-6545 | 1 Ipswitch | 1 Moveit | 2018-02-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to steal session cookies and launch client-side attacks. |