Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Debian Linux MEDIUM 6.1
CVE-2013-1951

A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web sc…

Fix: 1.19.5 / 1.20.4+
Fix from $1,600 2019-10-31
Debian Linux MEDIUM 5.4
CVE-2013-1934

A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote …

Fix: after 1.2.14
Fix from $1,600 2019-10-31
Debian Linux MEDIUM 6.1
CVE-2017-18635

An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the …

Fix: 0.6.2+
Fix from $1,600 2019-09-25
Debian Linux MEDIUM 6.1
CVE-2019-16728

DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.

Fix: 2.0.1+
Fix from $1,600 2019-09-24
Debian Linux MEDIUM 6.1
CVE-2019-13274

In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

Fix: after 4.3.28
Fix from $1,600 2019-08-27
Debian Linux MEDIUM 6.1
CVE-2019-12471

Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perfo…

Fix: 1.30.2 / 1.31.2+
Fix from $1,600 2019-07-10
Debian Linux MEDIUM 6.1
CVE-2019-13345EPSS 74%

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

Fix: after 4.7
Fix from $1,600 2019-07-05
Debian Linux MEDIUM 6.1
CVE-2019-10241EPSS 10%

In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES…

Fix: after 11.7.0
Fix from $1,600 2019-04-22
Debian Linux MEDIUM 5.4
CVE-2019-11025

In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options)…

Fix: 1.2.3+
Fix from $1,600 2019-04-08
Debian Linux MEDIUM 6.1
CVE-2019-10904

Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

No fix yet
Fix from $1,600 2019-04-06
Debian Linux MEDIUM 5.4
CVE-2018-18245

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plu…

No fix yet
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 6.1
CVE-2018-19970

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafte…

Fix: 4.8.4+
Fix from $1,600 2018-12-11
Debian Linux MEDIUM 6.1
CVE-2018-19787

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, al…

Fix: 4.2.5+
Fix from $1,600 2018-12-02
Debian Linux MEDIUM 6.1
CVE-2018-16471

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method…

Fix: 1.6.11 / 2.0.6+
Fix from $1,600 2018-11-13
Debian Linux MEDIUM 6.1
CVE-2018-19206EPSS 60%

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, with…

Fix: 1.3.8+
Fix from $1,600 2018-11-12
Debian Linux MEDIUM 5.4
CVE-2018-0618

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns…

Fix: after 2.1.26
Fix from $1,600 2018-07-26
Debian Linux MEDIUM 6.1
CVE-2018-14040

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Fix: 3.4.0 / 4.1.2+
Fix from $1,600 2018-07-13
Debian Linux MEDIUM 6.1
CVE-2018-1000528EPSS 46%

GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password fo…

Patch available
Fix from $1,600 2018-06-26
Debian Linux MEDIUM 5.4
CVE-2018-10060

Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.p…

Fix: after 1.1.36
Fix from $1,600 2018-04-12
Debian Linux MEDIUM 5.4
CVE-2018-10061

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape funct…

Fix: after 1.1.36
Fix from $1,600 2018-04-12
Debian Linux MEDIUM 6.1
CVE-2018-8048

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

Fix: 2.2.1+
Fix from $1,600 2018-03-27
Debian Linux MEDIUM 6.1
CVE-2018-8763

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or th…

Fix: 6.3+
Fix from $1,600 2018-03-27
Debian Linux MEDIUM 6.1
CVE-2018-1000078

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a…

Fix: after 2.5.0
Fix from $1,600 2018-03-13
Debian Linux MEDIUM 6.1
CVE-2017-18121

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that cou…

Fix: after 1.14.15
Fix from $1,600 2018-02-02
Debian Linux MEDIUM 6.1
CVE-2018-5950

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a …

Patch available
Fix from $1,600 2018-01-23
Debian Linux MEDIUM 6.1
CVE-2017-8808

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sen…

Fix: after 1.27.3
Fix from $1,600 2017-11-15
Debian Linux MEDIUM 6.1
CVE-2017-15568

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a c…

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15569

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a craft…

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15570

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.

Fix: after 3.2.7
Fix from $1,600 2017-10-18
Debian Linux MEDIUM 6.1
CVE-2017-15571

In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.

Fix: after 3.2.7
Fix from $1,600 2017-10-18