Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-14615 | 1 Watchguard | 1 Fireware | 2017-10-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user element, the code will be rendered in the context of any logged in user in the Web UI visiting "Traffic Monitor" sections "Events" and "All." As a side effect, no further events will be visible in the Traffic Monitor until the device is restarted. | |||||
CVE-2017-1425 | 1 Ibm | 1 Business Process Manager | 2017-10-03 | 3.5 LOW | 5.4 MEDIUM |
IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478. | |||||
CVE-2015-7316 | 1 Plone | 1 Plone | 2017-10-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1. | |||||
CVE-2013-6837 | 1 No-margin-for-errors | 1 Prettyphoto | 2017-10-02 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI. | |||||
CVE-2015-7347 | 1 Zcms Project | 1 Zcms | 2017-09-30 | 3.5 LOW | 4.8 MEDIUM |
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1. | |||||
CVE-2015-4706 | 1 Ipython | 1 Ipython | 2017-09-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path. | |||||
CVE-2017-14765 | 1 Genixcms | 1 Genixcms | 2017-09-29 | 4.3 MEDIUM | 6.1 MEDIUM |
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request. | |||||
CVE-2017-14761 | 1 Genixcms | 1 Genixcms | 2017-09-29 | 4.3 MEDIUM | 6.1 MEDIUM |
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter. | |||||
CVE-2017-14762 | 1 Genixcms | 1 Genixcms | 2017-09-29 | 4.3 MEDIUM | 6.1 MEDIUM |
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter. | |||||
CVE-2017-1530 | 1 Ibm | 1 Business Process Manager | 2017-09-29 | 3.5 LOW | 5.4 MEDIUM |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409. | |||||
CVE-2017-1531 | 1 Ibm | 1 Business Process Manager | 2017-09-29 | 3.5 LOW | 5.4 MEDIUM |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410. | |||||
CVE-2015-5282 | 1 Theforeman | 1 Foreman | 2017-09-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after. | |||||
CVE-2017-14142 | 1 Kaltura | 1 Kaltura Server | 2017-09-29 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to server/admin_console/web/tools/bigRedButton.php; the (3) partnerId, (4) playerVersion, (5) secret, (6) entryId, (7) adminUiConfId, or (8) uiConfId parameter to server/admin_console/web/tools/bigRedButtonPtsPoc.php; the (9) streamUsername, (10) streamPassword, (11) streamRemoteId, (12) streamRemoteBackupId, or (13) entryId parameter to server/admin_console/web/tools/AkamaiBroadcaster.php; the (14) entryId parameter to server/admin_console/web/tools/XmlJWPlayer.php; or the (15) partnerId or (16) playerVersion parameter to server/alpha/web/lib/bigRedButtonPtsPocHlsjs.php. | |||||
CVE-2009-0761 | 1 Team5.team Board | 6 1.0, 1.0.1, 1.0.2 and 3 more | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter. | |||||
CVE-2009-0763 | 1 Bookelves | 1 Kipper | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter. | |||||
CVE-2009-1067 | 1 Getpixie | 1 Pixie Cms | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter. | |||||
CVE-2009-1228 | 1 Arcadwy | 1 Arcadwy Arcade Script Cms | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter). | |||||
CVE-2009-1321 | 1 Humayun Shabbir Bhutta | 1 Asp Product Catalog | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | |||||
CVE-2009-1367 | 1 Mozilo | 1 Mozilocms | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue than CVE-2008-6127.2a. | |||||
CVE-2009-1451 | 1 Bluevirus-design | 1 Sma-db | 2017-09-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. |