Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-6348 | 1 Redhat | 1 Resteasy | 2017-04-19 | 4.3 MEDIUM | 6.1 MEDIUM |
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack. | |||||
CVE-2017-3125 | 1 Fortinet | 1 Fortimail | 2017-04-18 | 4.3 MEDIUM | 6.1 MEDIUM |
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker. | |||||
CVE-2017-7621 | 1 Auromeera | 1 Emli | 2017-04-17 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0. | |||||
CVE-2016-5055 | 1 Osram | 1 Lightify Pro | 2017-04-14 | 4.3 MEDIUM | 6.1 MEDIUM |
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page. | |||||
CVE-2016-5642 | 1 Opmantek | 1 Network Management Information System | 2017-04-14 | 3.5 LOW | 5.4 MEDIUM |
Opmantek NMIS before 8.5.12G has XSS via SNMP. | |||||
CVE-2016-5077 | 1 Netikus | 1 Eventsentry | 2017-04-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Netikus EventSentry before 3.2.1.44 has XSS via SNMP. | |||||
CVE-2015-6021 | 1 Spiceworks | 1 Desktop | 2017-04-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response. | |||||
CVE-2015-2883 | 1 Philips | 1 In.sight B120\\37 | 2017-04-14 | 3.5 LOW | 5.4 MEDIUM |
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php. | |||||
CVE-2015-7275 | 1 Dell | 4 Integrated Remote Access Controller 6, Integrated Remote Access Controller 7, Integrated Remote Access Controller 8 and 1 more | 2017-04-14 | 4.3 MEDIUM | 6.1 MEDIUM |
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS. | |||||
CVE-2016-5075 | 1 Cloudviewnms | 1 Cloudview Nms | 2017-04-14 | 4.3 MEDIUM | 6.1 MEDIUM |
CloudView NMS before 2.10a has XSS via a TELNET login. | |||||
CVE-2016-5073 | 1 Cloudviewnms | 1 Cloudview Nms | 2017-04-14 | 4.3 MEDIUM | 6.1 MEDIUM |
CloudView NMS before 2.10a has XSS via SNMP. | |||||
CVE-2015-6035 | 1 Opsview | 1 Opsview | 2017-04-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Opsview before 2015-11-06 has XSS via SNMP. | |||||
CVE-2017-7591 | 1 Openidm Project | 1 Openidm | 2017-04-13 | 4.3 MEDIUM | 6.1 MEDIUM |
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/. | |||||
CVE-2017-7579 | 1 Phpmyfaq | 1 Phpmyfaq | 2017-04-12 | 4.3 MEDIUM | 6.1 MEDIUM |
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field. | |||||
CVE-2016-1000307 | 1 Clip-bucket | 1 Clipbucket | 2017-04-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies, hobbies, fav_movies, fav_music, fav_books parameters to ProfileSettings page; (2) note parameter to PersonalNotes Section; (3) closed_msg, description, allowed_types parameters to WebsiteConfigurations Section. NOTE: the collection_description vector is already covered by CVE-2015-4673. | |||||
CVE-2015-4673 | 1 Clip-bucket | 1 Clipbucket | 2017-04-12 | 3.5 LOW | 5.4 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_description parameter to upload/manage_collections.php in an add_new action or the (2) photo_description, (3) photo_tags, or (4) photo_title parameter to upload/actions/photo_uploader.php. | |||||
CVE-2017-6340 | 1 Trendmicro | 1 Interscan Web Security Virtual Appliance | 2017-04-11 | 3.5 LOW | 5.4 MEDIUM |
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any authenticated, remote user (even with low privileges like 'Auditor') to create or modify reports, and consequently take advantage of this XSS vulnerability. The JavaScript is executed when victims visit reports or auditlog pages. | |||||
CVE-2016-5061 | 1 Aternity | 1 Aternity | 2017-04-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPAgent, (2) MacAgent, (3) getExternalURL, or (4) retrieveTrustedUrl page. | |||||
CVE-2017-7215 | 1 Misp Project | 1 Misp | 2017-04-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2016-7419 | 2 Nextcloud, Owncloud | 2 Nextcloud Server, Owncloud | 2017-04-07 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name. |