Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2024-32077 Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users a… Airflow Patch available Fix from $1,6002024-05-14 MEDIUM 6.1 CVE-2024-31868 Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal us… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-27140 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva… Archiva Mitigation only Fix from $1,6002024-03-01 MEDIUM 6.1 CVE-2023-50378 Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited … Ambari 2.7.8+ Fix from $1,6002024-03-01 MEDIUM 5.4 CVE-2024-23349 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer:… Answer after 1.2.1 Fix from $1,6002024-02-22 MEDIUM 5.4 CVE-2023-49657 A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on… Superset 3.0.3+ Fix from $1,6002024-01-23 MEDIUM 5.4 CVE-2023-47265 Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript… Airflow after 2.7.3 Fix from $1,6002023-12-21 MEDIUM 5.4 CVE-2023-49145 Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable … Nifi 1.24.0+ Fix from $1,6002023-11-27 MEDIUM 5.4 CVE-2023-43701 Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code int… Superset 2.1.2+ Fix from $1,6002023-11-27 MEDIUM 6.1 CVE-2023-45757 Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can sen… Brpc 1.6.1+ Fix from $1,6002023-10-16 MEDIUM 5.4 CVE-2023-37581 Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all … Roller 6.1.2+ Fix from $1,6002023-08-06 MEDIUM 6.1 CVE-2023-38435 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole… Felix Health Check Webconsole Plugin 2.1.0+ Fix from $1,6002023-07-25 MEDIUM 6.1 CVE-2022-46907 A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execut… Jspwiki 2.12.0+ Fix from $1,6002023-05-25 MEDIUM 5.4 CVE-2023-29247 Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. Airflow 2.6.0+ Fix from $1,6002023-05-08 CRITICAL 9.0 CVE-2022-45064 The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting is… Apache Sling Engine 2.14.0+ Fix from $2,3002023-04-13 MEDIUM 5.4 CVE-2023-28158 Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users… Archiva 2.2.10+ Fix from $1,6002023-03-29 MEDIUM 6.1 CVE-2023-22849 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and pri… Sling Cms 1.1.6+ Fix from $1,6002023-02-04 MEDIUM 5.4 CVE-2022-43717 Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-43718 Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with databas… Superset after 1.5.2 Fix from $1,6002023-01-16 MEDIUM 5.4 CVE-2022-46769 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and pri… Sling Cms 1.1.4+ Fix from $1,6002023-01-09 MEDIUM 6.1 CVE-2022-40743 Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting an… Traffic Server after 9.1.3 Fix from $1,6002022-12-19 MEDIUM 5.4 CVE-2022-46870 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to ex… Zeppelin 0.8.2+ Fix from $1,6002022-12-16 MEDIUM 5.4 CVE-2022-43670 An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and pri… Sling Cms after 1.1.0 Fix from $1,6002022-11-02 MEDIUM 6.1 CVE-2022-43982 In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. Airflow 2.4.2+ Fix from $1,6002022-11-02 MEDIUM 5.4 CVE-2022-34870 Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region … Geode after 1.15.0 Fix from $1,6002022-10-25 MEDIUM 6.1 CVE-2022-42466 Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be render… Isis 2.0.0+ Fix from $1,6002022-10-19 MEDIUM 5.4 CVE-2022-25370 Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.… Ofbiz 18.12.06+ Fix from $1,6002022-09-02 MEDIUM 6.1 CVE-2022-35278 In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by u… Artemis 2.24.0+ Fix from $1,6002022-08-23 MEDIUM 6.1 CVE-2022-27166EPSS 85% A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow … Jspwiki 2.11.3+ Fix from $1,6002022-08-04 MEDIUM 6.1 CVE-2022-28730EPSS 85% A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javasc… Jspwiki 2.11.3+ Fix from $1,6002022-08-04