Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-12705 1 Digisol 2 Dg-br4000ng, Dg-br4000ng Firmware 2018-08-30 4.3 MEDIUM 6.1 MEDIUM
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
CVE-2013-2999 1 Ibm 1 Infosphere Data Replication Dashboard 2018-08-29 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115.
CVE-2018-11351 1 Jirafeau 1 Jirafeau 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stored within the shared files description file and allow the execution of a JavaScript payload each time an administrator searches or lists uploaded files. These two injections could be triggered without authentication, and target the administrator. The attack vectors are the Content-Type field and the filename parameter.
CVE-2018-0499 2 Canonical, Xapian 2 Ubuntu Linux, Xapian-core 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
CVE-2018-11588 1 Centreon 2 Centreon, Centreon Web 2018-08-28 3.5 LOW 5.4 MEDIUM
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.
CVE-2018-1000529 1 Grails 1 Grails Fields 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.
CVE-2018-3748 1 Glance Project 1 Glance 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name.
CVE-2018-13433 1 Boostnote 1 Boostnote 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
CVE-2018-8738 1 Airties 4 5444, 5444 Firmware, 5444tt and 1 more 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
CVE-2018-7786 1 Schneider-electric 1 U.motion Builder 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts.
CVE-2018-13339 1 Angular Redactor Project 1 Angular Redactor 2018-08-28 4.3 MEDIUM 6.1 MEDIUM
Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.
CVE-2018-13422 1 Tecnick 1 Tcexam 2018-08-27 4.3 MEDIUM 6.1 MEDIUM
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
CVE-2018-13423 1 Omeka 1 Omeka 2018-08-27 4.3 MEDIUM 6.1 MEDIUM
admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag.
CVE-2018-1000536 1 Getmedis 1 Medis 2018-08-27 4.3 MEDIUM 6.1 MEDIUM
Medis version 0.6.1 and earlier contains a XSS vulnerability evolving into code execution due to enabled nodeIntegration for the renderer process vulnerability in Key name parameter on new key creation that can result in Unauthorized code execution in the victim's machine, within the rights of the running application. This attack appear to be exploitable via Victim is synchronizing data from the redis server which contains malicious key value.
CVE-2018-1000521 1 Bigtreecms 1 Bigtree Cms 2018-08-27 4.3 MEDIUM 6.1 MEDIUM
BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerability to attack high-privileged(Developer) users.. This attack appear to be exploitable via no. This vulnerability appears to have been fixed in after commit b652cfdc14d0670c81ac4401ad5a04376745c279.
CVE-2018-0605 1 Pixelpost 1 Pixelpost 2018-08-27 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-1299 1 Ibm 2 Rational Collaborative Lifecycle Management, Rational Quality Manager 2018-08-27 3.5 LOW 5.4 MEDIUM
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125161.
CVE-2018-1000604 1 Jenkins 1 Badge 2018-08-23 3.5 LOW 5.4 MEDIUM
A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
CVE-2018-13408 1 Jirafeau 1 Jirafeau 2018-08-23 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges.
CVE-2018-13409 1 Jirafeau 1 Jirafeau 2018-08-23 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges.