Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Syncope MEDIUM 5.4
CVE-2018-17184

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report …

Fix: 2.0.11 / 2.1.2+
Fix from $1,600 2018-11-06
Activemq MEDIUM 6.1
CVE-2018-8006EPSS 57%

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apa…

Fix: after 5.15.5
Fix from $1,600 2018-10-10
Airflow MEDIUM 6.1
CVE-2017-12614

It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and p…

Fix: 1.9.0+
Fix from $1,600 2018-08-06
Axis MEDIUM 6.1
CVE-2018-8032EPSS 11%

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Fix: after 1.4
Fix from $1,600 2018-08-02
Tomee MEDIUM 6.1
CVE-2018-8031

The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. Thi…

Fix: 7.0.5+
Fix from $1,600 2018-07-23
Hupa MEDIUM 6.1
CVE-2012-3536

Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a c…

Fix: 0.0.3+
Fix from $1,600 2018-02-27
Activemq MEDIUM 6.1
CVE-2016-6810EPSS 6%

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administratio…

Fix: 5.14.2+
Fix from $1,600 2018-01-10
Sling Xss Protection Api MEDIUM 6.1
CVE-2017-15717

A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#i…

Fix: after 1.0.18
Fix from $1,600 2018-01-10
Deltaspike MEDIUM 6.1
CVE-2017-17837

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 cha…

Patch available
Fix from $1,600 2018-01-04
Drill MEDIUM 5.4
CVE-2017-12630

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Pro…

Fix: after 1.11.0
Fix from $1,600 2017-12-18
Wicket MEDIUM 6.1
CVE-2012-5636

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers…

Patch available
Fix from $1,600 2017-10-30
Juddi MEDIUM 6.1
CVE-2009-1198

Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname par…

Fix: 2.0+
Fix from $1,600 2017-10-30
Nifi MEDIUM 5.4
CVE-2016-8748

In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an au…

Fix: after 1.0.0
Fix from $1,600 2017-10-19
Struts MEDIUM 6.1
CVE-2015-5169EPSS 7%

Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

Fix: after 2.3.16.3
Fix from $1,600 2017-09-25
Brooklyn MEDIUM 5.4
CVE-2017-3165

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the …

Fix: after 0.9.0
Fix from $1,600 2017-09-13
Ofbiz MEDIUM 6.1
CVE-2016-6800

The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to s…

Mitigation only
Fix from $1,600 2017-08-30
Atlas MEDIUM 6.1
CVE-2017-3150

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3151

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3152

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3153

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3155

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

Mitigation only
Fix from $1,600 2017-08-29
Sling Servlets Post MEDIUM 6.1
CVE-2017-9802

The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, whic…

Fix: after 2.3.20
Fix from $1,600 2017-08-14
Cxf MEDIUM 6.1
CVE-2016-6812EPSS 9%

The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists …

Fix: after 3.0.11
Fix from $1,600 2017-08-10
Sling MEDIUM 6.1
CVE-2016-5394

In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough …

Fix: 1.0.12+
Fix from $1,600 2017-07-19
Openmeetings HIGH 8.8
CVE-2017-7666

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings MEDIUM 6.1
CVE-2017-7663

Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

Mitigation only
Fix from $1,600 2017-07-17
Spark MEDIUM 6.1
CVE-2017-7678

In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link tha…

Fix: after 2.1.1
Fix from $1,600 2017-07-12
Nifi MEDIUM 6.1
CVE-2017-7665

In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS iss…

Fix: after 0.7.3
Fix from $1,600 2017-06-12
Hadoop MEDIUM 6.1
CVE-2017-3161

The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.

Fix: after 2.6.5
Fix from $1,600 2017-04-26
Guacamole MEDIUM 5.4
CVE-2016-1566

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by mult…

Mitigation only
Fix from $1,600 2017-02-02