Latest CVE Feed
-
5.4
MEDIUMCVE-2017-14985
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.php.... Read more
Affected Products : eyesofnetwork- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1553
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : infosphere_biginsights- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1567
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
- Published: Jan. 26, 2018
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2017-1629
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially ... Read more
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-16564
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor class ID field (P148).... Read more
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16568
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute... Read more
Affected Products : media_server- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16636
In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attackers are able to bypass the basic editor validation to trigger cross site scripting. The XSS is persistent... Read more
Affected Products : bludit- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1444
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
Affected Products : emptoris_sourcing- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-1911
IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin... Read more
Affected Products : rational_doors_next_generation- Published: Mar. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-15279
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/P... Read more
Affected Products : umbraco_cms- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUM- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1568
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering... Read more
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20875
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1678
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : rational_doors_next_generation- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16801
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.... Read more
Affected Products : octopus_deploy- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-25039
A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/RgUrlBlock.asp. The manipulation of the argument BasicParentalNewKeyword with the input ><script>alert... Read more
- Published: Jun. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-3716
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.... Read more
Affected Products : simplehttpserver- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18408
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18473
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-8178
Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability. A remote attacker could exploit this vulnerability to send email that storing malicious code to a smartphone an... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025