Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-12906 | 1 Nexusphp Project | 1 Nexusphp | 2017-09-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters.php or (2) confirm_resend.php. | |||||
CVE-2015-7252 | 1 Zte | 2 Zxhn H108n R1a, Zxhn H108n R1a Firmware | 2017-09-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter. | |||||
CVE-2015-6402 | 1 Cisco | 1 Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter | 2017-09-12 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935. | |||||
CVE-2015-3169 | 1 Askbot | 1 Askbot | 2017-09-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch. | |||||
CVE-2017-14193 | 1 Finecms Project | 1 Finecms | 2017-09-12 | 4.3 MEDIUM | 6.1 MEDIUM |
The oauth function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer. | |||||
CVE-2017-14192 | 1 Finecms Project | 1 Finecms | 2017-09-12 | 4.3 MEDIUM | 6.1 MEDIUM |
The checktitle function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the module field. | |||||
CVE-2017-14194 | 1 Finecms Project | 1 Finecms | 2017-09-12 | 4.3 MEDIUM | 6.1 MEDIUM |
The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer. | |||||
CVE-2017-14195 | 1 Finecms Project | 1 Finecms | 2017-09-12 | 4.3 MEDIUM | 6.1 MEDIUM |
The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with Internet Explorer. | |||||
CVE-2017-12879 | 1 Paessler | 1 Prtg Network Monitor | 2017-09-11 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2015-3161 | 1 Beaker-project | 1 Beaker | 2017-09-10 | 3.5 LOW | 4.8 MEDIUM |
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON. | |||||
CVE-2016-1915 | 1 Blackberry | 1 Blackberry Enterprise Service | 2017-09-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp. | |||||
CVE-2016-1941 | 2 Apple, Mozilla | 2 Mac Os X, Firefox | 2017-09-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended. | |||||
CVE-2015-0101 | 1 Ibm | 1 Business Process Manager | 2017-09-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5. | |||||
CVE-2017-9979 | 1 Osnexus | 1 Quantastor | 2017-09-07 | 4.3 MEDIUM | 6.1 MEDIUM |
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS. | |||||
CVE-2014-8078 | 1 Drupal | 1 Print | 2017-09-07 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes. | |||||
CVE-2014-9571 | 1 Mantisbt | 1 Mantisbt | 2017-09-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter. | |||||
CVE-2014-8505 | 1 Etiko | 1 Etiko Cms | 2017-09-07 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Etiko CMS allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to loja/index.php or (2) article_id parameter to index.php. | |||||
CVE-2014-8469 | 1 Moxi9 | 1 Phpfox | 2017-09-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header. | |||||
CVE-2014-6635 | 1 Exponentcms | 1 Exponent Cms | 2017-09-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the src parameter in the search action to index.php. | |||||
CVE-2014-7979 | 1 Drupal | 1 Simplecorp | 2017-09-07 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings. |