Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17320 1 Ucms Project 1 Ucms 2018-11-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.
CVE-2018-16147 1 Opsview 1 Opsview 2018-11-13 4.3 MEDIUM 6.1 MEDIUM
The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
CVE-2018-16148 1 Opsview 1 Opsview 2018-11-13 4.3 MEDIUM 6.1 MEDIUM
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
CVE-2018-0642 1 Foliovision 1 Fv Flowplayer Video Player 2018-11-13 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-17361 1 Weaselcms Project 1 Weaselcms 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is mishandled.
CVE-2018-4133 3 Apple, Canonical, Webkitgtk 3 Safari, Ubuntu Linux, Webkitgtk\+ 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2018-17002 1 Ricoh 2 Mp 2001sp, Mp 2001sp Firmware 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-17001 1 Ricoh 2 Sp 4510sf, Sp 4510sf Firmware 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-17003 1 Limesurvey 1 Limesurvey 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
CVE-2018-17322 1 Yunucms 1 Yunucms 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
CVE-2018-16965 1 Zohocorp 1 Manageengine Supportcenter Plus 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
CVE-2018-16833 1 Zohocorp 1 Manageengine Desktop Central 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
CVE-2018-16346 1 Chemcms Project 1 Chemcms 2018-11-09 3.5 LOW 4.8 MEDIUM
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
CVE-2018-9282 1 Subsonic 1 Subsonic 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.view; no administrator access is required. By injecting a JavaScript payload, this flaw could be used to manipulate a user's session, or elevate privileges by targeting an administrative user.
CVE-2018-11352 1 Wallabag 1 Wallabag 2018-11-09 2.1 LOW 4.0 MEDIUM
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.
CVE-2018-2464 1 Sap 1 Netweaver 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
CVE-2018-16955 1 Oracle 1 Webcenter Interaction 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// scheme, is unsafely reflected in a HTML META tag in the HTTP response. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
CVE-2018-16953 1 Oracle 1 Webcenter Interaction 2018-11-09 4.3 MEDIUM 6.1 MEDIUM
The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User input from the name parameter is unsafely reflected in the server response. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
CVE-2018-16327 1 Intelliants 1 Subrion 2018-11-09 3.5 LOW 4.8 MEDIUM
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
CVE-2018-17140 1 Vms-studio 1 Quizlord 2018-11-09 3.5 LOW 5.4 MEDIUM
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.