Latest CVE Feed
-
5.4
MEDIUMCVE-2022-31792
A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted reque... Read more
Affected Products : fireware- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1305
IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
Affected Products : rational_doors_next_generation- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1334
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : rational_engineering_lifecycle_manager- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1502
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo... Read more
Affected Products : content_navigator- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15213
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.... Read more
Affected Products : flyspray- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15727
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.... Read more
Affected Products : phpmyfaq- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-10806
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).... Read more
Affected Products : cpanel- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10822
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10851
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3810
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Rele... Read more
Affected Products : prime_service_catalog- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15312
Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote authenticated attacker could exploit this vulnerability to inject malicious scripts in the affected device.... Read more
Affected Products : smartcare- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-1999030
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attacker... Read more
Affected Products : maven_artifact_choicelistprovider_\(nexus\)- Published: Aug. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-20368
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.... Read more
Affected Products : master_slider- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-17995
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.... Read more
Affected Products : biometric_shift_employee_management_system- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-18034
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabilit... Read more
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18176
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.... Read more
Affected Products : sitefinity- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-5690
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the nb parameter (aka the page limit number).... Read more
Affected Products : dotclear- Published: Jan. 14, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-9548
admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page th... Read more
Affected Products : bigtree_cms- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-6866
Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a crafted message.... Read more
Affected Products : learning_and_examination_management_system_script- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-7188
An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php.... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024