Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Openmeetings MEDIUM 6.1
CVE-2016-3089

Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script …

Fix: after 3.1.1
Fix from $1,600 2016-08-19
Activemq MEDIUM 5.4
CVE-2016-0782EPSS 6%

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users…

No fix yet
Fix from $1,600 2016-08-05
Wicket MEDIUM 6.1
CVE-2015-7520EPSS 5%

Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15…

Fix: 1.5.15 / 6.22.0+
Fix from $1,600 2016-04-12
Wicket MEDIUM 6.1
CVE-2015-5347EPSS 8%

Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow i…

Fix: 1.5.15 / 6.22.0+
Fix from $1,600 2016-04-12
Struts MEDIUM 6.1
CVE-2016-4003EPSS 12%

Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a singl…

Fix: after 2.3.24.1
Fix from $1,600 2016-04-12
Struts MEDIUM 6.1
CVE-2016-2162EPSS 8%

Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con…

Mitigation only
Fix from $1,600 2016-04-12
Ofbiz MEDIUM 6.1
CVE-2015-3268EPSS 9%

Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 1…

Patch available
Fix from $1,600 2016-04-12
Ranger MEDIUM 6.1
CVE-2015-0265

Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web scrip…

Fix: after 0.4.0
Fix from $1,600 2016-04-11
Openmeetings MEDIUM 6.1
CVE-2016-2163EPSS 8%

Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the e…

Fix: after 3.1.0
Fix from $1,600 2016-04-11
Jetspeed MEDIUM 6.1
CVE-2016-0712

Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_…

Fix: after 2.3.0
Fix from $1,600 2016-04-11
Jetspeed MEDIUM 6.1
CVE-2016-0711

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via…

Fix: after 2.3.0
Fix from $1,600 2016-04-11
Solr MEDIUM 6.1
CVE-2015-8797

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows rem…

Fix: after 5.3
Fix from $1,600 2016-02-15
Solr MEDIUM 6.1
CVE-2015-8796

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers…

Fix: after 5.2.1
Fix from $1,600 2016-02-15
Solr MEDIUM 6.1
CVE-2015-8795

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script o…

Fix: after 5.0
Fix from $1,600 2016-02-15
Archiva MEDIUM 6.8
CVE-2010-4408

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password …

Mitigation only
Fix from $1,600 2010-12-06
HTTP Server MEDIUM 6.1
CVE-2007-4465EPSS 26%

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is no…

Fix: 2.0.61 / 2.2.6+
Fix from $1,600 2007-09-14