Total
30469 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-6392 | 6 Debian, Fedoraproject, Google and 3 more | 9 Debian Linux, Fedora, Chrome and 6 more | 2024-02-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. | |||||
CVE-2018-17572 | 1 Influxdata | 1 Influxdb | 2024-02-28 | 3.5 LOW | 4.8 MEDIUM |
InfluxDB 0.9.5 has Reflected XSS in the Write Data module. | |||||
CVE-2020-10430 | 1 Chadhaajay | 1 Phpkb | 2024-02-28 | 3.5 LOW | 4.8 MEDIUM |
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-subscribers.php by adding a question mark (?) followed by the payload. | |||||
CVE-2020-5842 | 1 Codologic | 1 Codoforum | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page. | |||||
CVE-2020-10417 | 1 Chadhaajay | 1 Phpkb | 2024-02-28 | 3.5 LOW | 4.8 MEDIUM |
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-articles.php by adding a question mark (?) followed by the payload. | |||||
CVE-2020-5193 | 1 Phpgurukul | 1 Hospital Management System | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter. | |||||
CVE-2019-18249 | 1 Reliablecontrols | 4 Mach-prowebcom, Mach-prowebcom Firmware, Mach-prowebsys and 1 more | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on a malicious link. | |||||
CVE-2020-10191 | 1 Munkireport Project | 1 Munkireport | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /module/comment/save endpoint. The payload will be executed by any authenticated users browsing the application. This concerns app/controllers/client.php:detail. | |||||
CVE-2016-6588 | 1 Symantec | 1 It Management Suite | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0. | |||||
CVE-2019-20072 | 1 Netis-systems | 2 Dl4343, Dl4343 Firmware | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration). | |||||
CVE-2019-18842 | 1 Usriot | 8 Usr-wifi232-g2, Usr-wifi232-g2 Firmware, Usr-wifi232-h and 5 more | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi access point nearby with a malicious SSID. | |||||
CVE-2020-10437 | 1 Chadhaajay | 1 Phpkb | 2024-02-28 | 3.5 LOW | 4.8 MEDIUM |
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/optimize-database.php by adding a question mark (?) followed by the payload. | |||||
CVE-2013-2637 | 2 Opensuse, Otrs | 3 Opensuse, Faq, Otrs Itsm | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code. | |||||
CVE-2019-14862 | 3 Knockoutjs, Oracle, Redhat | 5 Knockout, Business Intelligence, Goldengate and 2 more | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it. | |||||
CVE-2011-1086 | 1 Openfiler | 1 Openfiler | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter. | |||||
CVE-2011-3595 | 1 Joomla | 1 Joomla\! | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters. | |||||
CVE-2020-1697 | 1 Redhat | 2 Keycloak, Single Sign-on | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks. | |||||
CVE-2019-7621 | 1 Elastic | 1 Kibana | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser. | |||||
CVE-2019-18588 | 1 Dell | 2 Emc Powermax, Emc Unisphere For Powermax | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users' sessions. | |||||
CVE-2020-7208 | 1 Hp | 1 Linuxki | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2. |