Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-3618 1 Nagios 1 Business Process Intelligence 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
CVE-2015-3619 1 Virtuemart 1 Virtuemart 2018-02-26 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company."
CVE-2018-6291 1 Kaspersky 1 Secure Mail Gateway 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
CVE-2017-5124 2 Debian, Google 2 Debian Linux, Chrome 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
CVE-2017-8783 1 Synacor 1 Zimbra Collaboration Suite 2018-02-23 3.5 LOW 5.4 MEDIUM
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
CVE-2017-17703 1 Synacor 1 Zimbra Collaboration Suite 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
CVE-2013-6459 1 Mislav Marohnic 1 Will Paginate 2018-02-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.
CVE-2018-6355 1 Iball 2 Ib-wrb302n, Ib-wrb302n Firmware 2018-02-21 4.3 MEDIUM 6.1 MEDIUM
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
CVE-2016-4318 1 Atlassian 1 Jira 2018-02-15 3.5 LOW 4.8 MEDIUM
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CVE-2016-4317 1 Atlassian 1 Confluence 2018-02-15 3.5 LOW 5.4 MEDIUM
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CVE-2018-6354 1 Formspree 1 Formspree 2018-02-15 4.3 MEDIUM 6.1 MEDIUM
templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.
CVE-2018-6465 1 Wp-property-hive 1 Propertyhive 2018-02-15 4.3 MEDIUM 6.1 MEDIUM
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
CVE-2017-18083 1 Atlassian 1 Confluence 2018-02-15 3.5 LOW 5.4 MEDIUM
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
CVE-2018-6561 1 Dojotoolkit 1 Dojo 2018-02-15 4.3 MEDIUM 6.1 MEDIUM
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
CVE-2016-0303 1 Ibm 1 Tivoli Integrated Portal 2018-02-15 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-6194 1 Splashing Images Project 1 Splashing Images 2018-02-14 3.5 LOW 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search parameter to wp-admin/upload.php.
CVE-2016-0311 1 Ibm 1 Tivoli Business Service Manager 2018-02-14 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480.
CVE-2018-0508 1 Kkcald Project 1 Kkcald 2018-02-14 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-6550 1 Monstra 1 Monstra 2018-02-14 3.5 LOW 5.4 MEDIUM
Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
CVE-2018-6545 1 Ipswitch 1 Moveit 2018-02-14 4.3 MEDIUM 6.1 MEDIUM
Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to steal session cookies and launch client-side attacks.