Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2018-17184 A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report … Syncope 2.0.11 / 2.1.2+ Fix from $1,6002018-11-06 MEDIUM 6.1 CVE-2018-8006EPSS 57% An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apa… Activemq after 5.15.5 Fix from $1,6002018-10-10 MEDIUM 6.1 CVE-2017-12614 It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and p… Airflow 1.9.0+ Fix from $1,6002018-08-06 MEDIUM 6.1 CVE-2018-8032EPSS 11% Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. Axis after 1.4 Fix from $1,6002018-08-02 MEDIUM 6.1 CVE-2018-8031 The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. Thi… Tomee 7.0.5+ Fix from $1,6002018-07-23 MEDIUM 6.1 CVE-2012-3536 Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a c… Hupa 0.0.3+ Fix from $1,6002018-02-27 MEDIUM 6.1 CVE-2016-6810EPSS 6% In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administratio… Activemq 5.14.2+ Fix from $1,6002018-01-10 MEDIUM 6.1 CVE-2017-15717 A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#i… Sling Xss Protection Api after 1.0.18 Fix from $1,6002018-01-10 MEDIUM 6.1 CVE-2017-17837 The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 cha… Deltaspike Patch available Fix from $1,6002018-01-04 MEDIUM 5.4 CVE-2017-12630 In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Pro… Drill after 1.11.0 Fix from $1,6002017-12-18 MEDIUM 6.1 CVE-2012-5636 Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers… Wicket Patch available Fix from $1,6002017-10-30 MEDIUM 6.1 CVE-2009-1198 Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname par… Juddi 2.0+ Fix from $1,6002017-10-30 MEDIUM 5.4 CVE-2016-8748 In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an au… Nifi after 1.0.0 Fix from $1,6002017-10-19 MEDIUM 6.1 CVE-2015-5169EPSS 7% Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20. Struts after 2.3.16.3 Fix from $1,6002017-09-25 MEDIUM 5.4 CVE-2017-3165 In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the … Brooklyn after 0.9.0 Fix from $1,6002017-09-13 MEDIUM 6.1 CVE-2016-6800 The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to s… Ofbiz Mitigation only Fix from $1,6002017-08-30 MEDIUM 6.1 CVE-2017-3150 Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script. Atlas Mitigation only Fix from $1,6002017-08-29 MEDIUM 6.1 CVE-2017-3151 Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. Atlas Mitigation only Fix from $1,6002017-08-29 MEDIUM 6.1 CVE-2017-3152 Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality. Atlas Mitigation only Fix from $1,6002017-08-29 MEDIUM 6.1 CVE-2017-3153 Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality. Atlas Mitigation only Fix from $1,6002017-08-29 MEDIUM 6.1 CVE-2017-3155 Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting. Atlas Mitigation only Fix from $1,6002017-08-29 MEDIUM 6.1 CVE-2017-9802 The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, whic… Sling Servlets Post after 2.3.20 Fix from $1,6002017-08-14 MEDIUM 6.1 CVE-2016-6812EPSS 9% The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists … Cxf after 3.0.11 Fix from $1,6002017-08-10 MEDIUM 6.1 CVE-2016-5394 In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough … Sling 1.0.12+ Fix from $1,6002017-07-19 HIGH 8.8 CVE-2017-7666 Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. Openmeetings Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-7663 Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. Openmeetings Mitigation only Fix from $1,6002017-07-17 MEDIUM 6.1 CVE-2017-7678 In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link tha… Spark after 2.1.1 Fix from $1,6002017-07-12 MEDIUM 6.1 CVE-2017-7665 In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS iss… Nifi after 0.7.3 Fix from $1,6002017-06-12 MEDIUM 6.1 CVE-2017-3161 The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter. Hadoop after 2.6.5 Fix from $1,6002017-04-26 MEDIUM 5.4 CVE-2016-1566 Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by mult… Guacamole Mitigation only Fix from $1,6002017-02-02