Total
34649 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2017-13073 | 1 Qnap | 1 Photo Station | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML. | |||||
| CVE-2018-10268 | 1 Fastadmin | 1 Fastadmin | 2018-05-25 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter. | |||||
| CVE-2018-6518 | 1 Compo | 1 Composr Cms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
| Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php. | |||||
| CVE-2017-1724 | 1 Ibm | 5 Qradar Incident Forensics, Qradar Network Insights, Qradar Risk Manager and 2 more | 2018-05-25 | 3.5 LOW | 6.1 MEDIUM |
| IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814. | |||||
| CVE-2018-10329 | 1 Phpipam | 1 Phpipam | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. | |||||
| CVE-2018-10366 | 1 User Project | 1 User | 2018-05-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field. | |||||
| CVE-2018-10422 | 1 Hongcms Project | 1 Hongcms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field. | |||||
| CVE-2017-14740 | 1 Genixcms | 1 Genixcms | 2018-05-25 | 3.5 LOW | 4.8 MEDIUM |
| Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu. | |||||
| CVE-2014-2908 | 1 Siemens | 6 Simatic S7 Cpu-1211c, Simatic S7 Cpu 1200 Firmware, Simatic S7 Cpu 1212c and 3 more | 2018-05-25 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2017-15640 | 1 Phpipam | 1 Phpipam | 2018-05-24 | 3.5 LOW | 5.4 MEDIUM |
| app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter. | |||||
| CVE-2018-9103 | 1 Mitel | 2 Mivoice Connect, St 14.2 | 2018-05-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts. | |||||
| CVE-2018-9101 | 1 Mitel | 2 Mivoice Connect, St 14.2 | 2018-05-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the launch_presenter.php page. A successful exploit could allow an attacker to execute arbitrary scripts. | |||||
| CVE-2018-10234 | 1 Ultimatemember | 1 User Profile \& Membership | 2018-05-24 | 3.5 LOW | 4.8 MEDIUM |
| Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | |||||
| CVE-2017-17889 | 1 Kliqqi | 1 Kliqqi Cms | 2018-05-24 | 3.5 LOW | 5.4 MEDIUM |
| Kliqqi CMS 3.5.2 has XSS via a crafted group name in pligg/groups.php, a crafted Homepage string in a profile, or a crafted string in Tags or Description within pligg/submit.php. | |||||
| CVE-2018-9104 | 1 Mitel | 2 Mivoice Connect, St 14.2 | 2018-05-24 | 4.3 MEDIUM | 6.1 MEDIUM |
| A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the api.php page. A successful exploit could allow an attacker to execute arbitrary scripts. | |||||
| CVE-2018-10374 | 1 Easycms | 1 Easycms | 2018-05-23 | 4.3 MEDIUM | 6.1 MEDIUM |
| EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request. | |||||
| CVE-2018-8831 | 1 Kodi | 1 Kodi | 2018-05-22 | 4.3 MEDIUM | 6.1 MEDIUM |
| A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist. | |||||
| CVE-2015-1952 | 1 Ibm | 1 Security Appscan | 2018-05-22 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416. | |||||
| CVE-2018-1445 | 1 Ibm | 1 Websphere Portal | 2018-05-22 | 3.5 LOW | 5.4 MEDIUM |
| IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907. | |||||
| CVE-2018-10221 | 1 Wuzhicms | 1 Wuzhicms | 2018-05-21 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload. | |||||
