Latest CVE Feed
-
5.4
MEDIUMCVE-2021-21442
In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.... Read more
Affected Products : time_accounting- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21668
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.... Read more
Affected Products : scriptler- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-12221
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due t... Read more
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-21377
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to... Read more
Affected Products : omero.web- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21365
Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability. Users of the extension, who have ove... Read more
Affected Products : typo3- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21370
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their referenced item... Read more
Affected Products : typo3- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21340
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content gets previewed. A v... Read more
Affected Products : typo3- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-8522
A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.... Read more
Affected Products : diagnostics- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-8532
A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.... Read more
Affected Products : matrix_operating_environment- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-0241
An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to t... Read more
Affected Products : edge- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-21283
Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site scripting vulnerability. A change in release beta 14 of the Sticky extension caused the plain text content o... Read more
Affected Products : sticky- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-9316
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote u... Read more
Affected Products : interscan_web_security_virtual_appliance- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8316
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows low... Read more
Affected Products : flexcube_investor_servicing- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-20857
Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20843
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settin... Read more
Affected Products : rtx830_firmware nvr510_firmware nvr700w_firmware rtx1210_firmware biz_box_rtx830_firmware biz_box_nvr510_firmware biz_box_nvr700w_firmware biz_box_rtx1210_firmware rtx830 nvr510 +6 more products- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20856
Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20800
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20803
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20798
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20797
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024