Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-3296 | 1 Nodebb | 1 Nodebb | 2017-09-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs. | |||||
CVE-2017-14621 | 1 Suse | 1 Portus | 2017-09-28 | 3.5 LOW | 5.4 MEDIUM |
Portus 2.2.0 has XSS via the Team field, related to typeahead. | |||||
CVE-2017-14715 | 1 Telaxius | 1 Epesi | 2017-09-28 | 3.5 LOW | 5.4 MEDIUM |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter. | |||||
CVE-2017-14716 | 1 Telaxius | 1 Epesi | 2017-09-28 | 3.5 LOW | 5.4 MEDIUM |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter. | |||||
CVE-2017-14714 | 1 Telaxius | 1 Epesi | 2017-09-28 | 3.5 LOW | 5.4 MEDIUM |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter. | |||||
CVE-2017-14713 | 1 Telaxius | 1 Epesi | 2017-09-28 | 3.5 LOW | 5.4 MEDIUM |
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter. | |||||
CVE-2015-1866 | 1 Emberjs | 1 Ember.js | 2017-09-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2. | |||||
CVE-2017-3165 | 1 Apache | 1 Brooklyn | 2017-09-27 | 3.5 LOW | 5.4 MEDIUM |
In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper escaping of server-side content. There is known to be a proof-of-concept exploit using this vulnerability. | |||||
CVE-2015-3162 | 1 Beaker-project | 1 Beaker | 2017-09-25 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users to inject arbitrary web script or HTML via writing a crafted comment on an acked or nacked canceled job. | |||||
CVE-2015-3299 | 1 Floating Social Bar Project | 1 Floating Social Bar | 2017-09-25 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order. | |||||
CVE-2014-6191 | 1 Ibm | 1 Curam Social Program Management | 2017-09-23 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568. | |||||
CVE-2015-3432 | 1 Pydio | 1 Pydio | 2017-09-23 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Pydio (formerly AjaXplorer) before 6.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Pydio XSS Vulnerabilities." | |||||
CVE-2015-0549 | 1 Emc | 1 Documentum D2 | 2017-09-22 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before 4.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-1159 | 1 Cups | 1 Cups | 2017-09-22 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/. | |||||
CVE-2015-0526 | 1 Emc | 1 Rsa Validation Manager | 2017-09-22 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Validation Manager (RVM) 3.2 before build 201 allow remote attackers to inject arbitrary web script or HTML via the (1) displayMode or (2) wrapPreDisplayMode parameter. | |||||
CVE-2015-4072 | 1 Helpdesk Pro Project | 1 Helpdesk Pro | 2017-09-22 | 3.5 LOW | 5.4 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message. | |||||
CVE-2017-14597 | 1 Afterlogic | 2 Aurora, Webmail | 2017-09-22 | 3.5 LOW | 4.8 MEDIUM |
AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/ajax.php during addition of a domain. | |||||
CVE-2015-1917 | 1 Ibm | 1 Websphere Portal | 2017-09-21 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |||||
CVE-2015-4528 | 1 Emc | 1 Documentum Centerstage | 2017-09-21 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in EMC Documentum CenterStage 1.2SP1 and 1.2SP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2014-0611 | 1 Novell | 1 Groupwise | 2017-09-21 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |