Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-5055 1 Osram 1 Lightify Pro 2017-04-14 4.3 MEDIUM 6.1 MEDIUM
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
CVE-2016-5642 1 Opmantek 1 Network Management Information System 2017-04-14 3.5 LOW 5.4 MEDIUM
Opmantek NMIS before 8.5.12G has XSS via SNMP.
CVE-2016-5077 1 Netikus 1 Eventsentry 2017-04-14 4.3 MEDIUM 6.1 MEDIUM
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
CVE-2015-6021 1 Spiceworks 1 Desktop 2017-04-14 4.3 MEDIUM 6.1 MEDIUM
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
CVE-2015-2883 1 Philips 1 In.sight B120\\37 2017-04-14 3.5 LOW 5.4 MEDIUM
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.
CVE-2015-7275 1 Dell 4 Integrated Remote Access Controller 6, Integrated Remote Access Controller 7, Integrated Remote Access Controller 8 and 1 more 2017-04-14 4.3 MEDIUM 6.1 MEDIUM
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
CVE-2016-5075 1 Cloudviewnms 1 Cloudview Nms 2017-04-14 4.3 MEDIUM 6.1 MEDIUM
CloudView NMS before 2.10a has XSS via a TELNET login.
CVE-2016-5073 1 Cloudviewnms 1 Cloudview Nms 2017-04-14 4.3 MEDIUM 6.1 MEDIUM
CloudView NMS before 2.10a has XSS via SNMP.
CVE-2015-6035 1 Opsview 1 Opsview 2017-04-13 4.3 MEDIUM 6.1 MEDIUM
Opsview before 2015-11-06 has XSS via SNMP.
CVE-2017-7591 1 Openidm Project 1 Openidm 2017-04-13 4.3 MEDIUM 6.1 MEDIUM
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
CVE-2017-7579 1 Phpmyfaq 1 Phpmyfaq 2017-04-12 4.3 MEDIUM 6.1 MEDIUM
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.
CVE-2015-4673 1 Clip-bucket 1 Clipbucket 2017-04-12 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_description parameter to upload/manage_collections.php in an add_new action or the (2) photo_description, (3) photo_tags, or (4) photo_title parameter to upload/actions/photo_uploader.php.
CVE-2016-1000307 1 Clip-bucket 1 Clipbucket 2017-04-12 4.3 MEDIUM 6.1 MEDIUM
Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies, hobbies, fav_movies, fav_music, fav_books parameters to ProfileSettings page; (2) note parameter to PersonalNotes Section; (3) closed_msg, description, allowed_types parameters to WebsiteConfigurations Section. NOTE: the collection_description vector is already covered by CVE-2015-4673.
CVE-2017-6340 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2017-04-11 3.5 LOW 5.4 MEDIUM
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any authenticated, remote user (even with low privileges like 'Auditor') to create or modify reports, and consequently take advantage of this XSS vulnerability. The JavaScript is executed when victims visit reports or auditlog pages.
CVE-2016-5061 1 Aternity 1 Aternity 2017-04-10 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPAgent, (2) MacAgent, (3) getExternalURL, or (4) retrieveTrustedUrl page.
CVE-2017-7215 1 Misp Project 1 Misp 2017-04-07 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML.
CVE-2016-7419 2 Nextcloud, Owncloud 2 Nextcloud Server, Owncloud 2017-04-07 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.
CVE-2016-0218 1 Ibm 1 Cognos Business Intelligence 2017-04-06 3.5 LOW 5.4 MEDIUM
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2016-8789 1 Huawei 2 Espace Integrated Access Device, Espace Integrated Access Device Firmware 2017-04-05 4.3 MEDIUM 6.1 MEDIUM
Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.
CVE-2017-7387 1 Helpmewatchwho Project 1 Helpmewatchwho 2017-04-05 4.3 MEDIUM 6.1 MEDIUM
TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).