Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-2162 1 Apache 1 Struts 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
CVE-2016-1598 1 Novell 2 Identity Manager, Identity Manager Identity Applications 2016-11-28 3.5 LOW 5.4 MEDIUM
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
CVE-2016-1205 1 Shiro8 2 Category Freearea Addition, Itemdetail Freearea Addition 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the shiro8 (1) category_freearea_ addition_plugin plugin 1.0 and (2) itemdetail_freearea_ addition_plugin plugin 1.0 for EC-CUBE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-1000146 1 Pondol-formmail Project 1 Pondol-formmail 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin pondol-formmail v1.1
CVE-2016-1000148 1 S3-video Project 1 S3-video 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin s3-video v0.983
CVE-2016-1000141 1 Page-layout-builder Project 1 Page-layout-builder 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin page-layout-builder v1.9.3
CVE-2016-1000143 1 Photoxhibit Project 1 Photoxhibit 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin photoxhibit v2.1.8
CVE-2016-1000149 1 Simpel-reserveren Project 1 Simpel-reserveren 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin simpel-reserveren v3.5.2
CVE-2016-1000154 1 Browserweb 1 Whizz 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin whizz v1.0.7
CVE-2016-1000140 1 New-year-firework Project 1 New-year-firework 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin new-year-firework v1.1.9
CVE-2016-1000121 1 Huge-it 1 Slider 2016-11-28 3.5 LOW 4.8 MEDIUM
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000138 1 Indexisto Project 1 Indexisto 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin indexisto v1.0.5
CVE-2016-1000126 1 Admin-font-editor Project 1 Admin-font-editor 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin admin-font-editor v1.8
CVE-2016-1000129 1 Defa-online-image-protector Project 1 Defa-online-image-protector 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin defa-online-image-protector v3.3
CVE-2016-1000127 1 Ajax-random-post Project 1 Ajax-random-post 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin ajax-random-post v2.00
CVE-2016-0370 1 Ibm 1 Forms Experience Builder 2016-11-28 3.5 LOW 2.7 LOW
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
CVE-2016-0387 1 Ibm 1 Tririga Application Platform 2016-11-28 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883.
CVE-2016-0269 1 Ibm 1 Bigfix Platform 2016-11-28 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-0246 1 Ibm 1 Security Guardium 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-0293 1 Ibm 1 Bigfix Platform 2016-11-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.