Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2019-17557
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user acce…
Syncope
2.0.15 / 2.1.6+
MEDIUM 6.1
CVE-2020-1943EPSS 97%
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Ofbiz
after 16.11.07
MEDIUM 6.1
CVE-2020-1949
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative c…
Sling Cms
0.16.0+
MEDIUM 6.1
CVE-2015-2992EPSS 6%
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Struts
2.3.20+
MEDIUM 6.1
CVE-2020-1933
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticate…
Nifi
after 1.10.0
MEDIUM 6.1
CVE-2019-17573EPSS 7%
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…
Cxf
3.3.5+
MEDIUM 6.1
CVE-2019-10070
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
Atlas
Mitigation only
MEDIUM 6.1
CVE-2019-10092EPSS 81%
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the…
HTTP Server
after 9.5
MEDIUM 6.1
CVE-2019-10090
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …
Jspwiki
after 2.10.5
MEDIUM 6.1
CVE-2019-12407
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …
Jspwiki
after 2.10.5
MEDIUM 6.1
CVE-2019-10087
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …
Jspwiki
after 2.10.5
MEDIUM 6.1
CVE-2019-10089
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …
Jspwiki
after 2.10.5
MEDIUM 6.1
CVE-2019-12404
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …
Jspwiki
after 2.10.5
MEDIUM 6.1
CVE-2019-10073EPSS 5%
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation:…
Ofbiz
after 16.11.05
MEDIUM 6.1
CVE-2019-12397
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apach…
Ranger
after 1.2.0
MEDIUM 6.1
CVE-2019-0234
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…
Roller
Mitigation only
MEDIUM 6.1
CVE-2019-10085EPSS 5%
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS execu…
Allura
1.11.0+
MEDIUM 6.1
CVE-2019-0221EPSS 46%
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is…
Tomcat
after 9.0.17
MEDIUM 6.1
CVE-2019-10076
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacki…
Jspwiki
after 2.11.0
MEDIUM 6.1
CVE-2019-10077
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
Jspwiki
after 2.11.0
MEDIUM 6.1
CVE-2019-10078
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijac…
Jspwiki
after 2.11.0
MEDIUM 6.1
CVE-2018-8035
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which ru…
Uimaducc
after 2.2.2
MEDIUM 6.5
CVE-2019-0213
In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerabili…
Archiva
2.2.4+
MEDIUM 6.1
CVE-2019-0186EPSS 21%
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni…
Pluto
No fix yet
MEDIUM 6.1
CVE-2018-1328EPSS 6%
Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
Zeppelin
0.8.0+
MEDIUM 6.1
CVE-2019-0218EPSS 5%
A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.
Pony Mail
after 0.10
MEDIUM 6.1
CVE-2019-0224EPSS 5%
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on th…
Jspwiki
after 2.10.5
MEDIUM 5.5
CVE-2018-20244
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascr…
Airflow
1.10.2+
MEDIUM 6.1
CVE-2018-20242EPSS 5%
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
Jspwiki
after 2.10.5
MEDIUM 6.1
CVE-2018-17193
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attac…
Nifi
after 1.7.1