Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
HIGH 7.5 CVE-2020-35475 In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits… Debian Linux 1.35.1+ Fix from $1,9502020-12-18 MEDIUM 6.1 CVE-2020-35479 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, t… Debian Linux 1.35.1+ Fix from $1,6002020-12-18 MEDIUM 6.1 CVE-2020-25706 A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template im… Debian Linux Patch available Fix from $1,6002020-11-12 MEDIUM 6.1 CVE-2020-26870 Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree… Debian Linux 2.0.17 / 21.1.0.00.01+ Fix from $1,6002020-10-07 MEDIUM 6.1 CVE-2020-15562 An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail mess… Debian Linux 1.2.11 / 1.3.14+ Fix from $1,6002020-07-06 MEDIUM 5.4 CVE-2020-4051 In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8,… Debian Linux 1.11.11 / 1.12.9+ Fix from $1,6002020-06-15 MEDIUM 6.1 CVE-2020-13965 KEVEPSS 77% An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am… Debian Linux 1.3.12 / 1.4.5+ Fix from $1,6002020-06-09 MEDIUM 6.1 CVE-2020-11082 In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has b… Debian Linux 1.2.1+ Fix from $1,6002020-05-28 MEDIUM 6.1 CVE-2020-8020 A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code … Debian Linux 2020-05-13+ Fix from $1,6002020-05-13 MEDIUM 6.1 CVE-2020-12625 An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScrip… Debian Linux 1.4.4+ Fix from $1,6002020-05-04 MEDIUM 6.1 CVE-2020-11029 In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scriptin… Debian Linux 3.7.33 / 3.8.33+ Fix from $1,6002020-04-30 MEDIUM 6.1 CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a… Debian Linux 2.1.30+ Fix from $1,6002020-04-24 MEDIUM 5.4 CVE-2020-10803 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS… Debian Linux 4.9.5 / 5.0.2+ Fix from $1,6002020-03-22 MEDIUM 6.1 CVE-2019-10785 dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xm… Debian Linux 1.11.9 / 1.12.7+ Fix from $1,6002020-02-13 MEDIUM 6.1 CVE-2020-7106 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and us… Debian Linux 1.2.9+ Fix from $1,6002020-01-16 MEDIUM 6.1 CVE-2020-1766 Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious java… Debian Linux after 7.0.13 Fix from $1,6002020-01-10 MEDIUM 6.1 CVE-2012-2237 Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary we… Debian Linux 1.4.3 / 1.5.2+ Fix from $1,6002019-12-17 MEDIUM 6.1 CVE-2014-4913 ZF2014-03 has a potential cross site scripting vector in multiple view helpers Debian Linux 2.2.7 / 2.3.1+ Fix from $1,6002019-12-15 CRITICAL 9.3 CVE-2019-18345 A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied… Debian Linux after 1.1.8 Fix from $2,3002019-12-12 MEDIUM 6.1 CVE-2013-7371 node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) Debian Linux 2.8.2+ Fix from $1,6002019-12-11 MEDIUM 6.1 CVE-2013-4158 smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) Debian Linux 2.6.9+ Fix from $1,6002019-12-11 MEDIUM 6.1 CVE-2012-1114 A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_… Debian Linux Mitigation only Fix from $1,6002019-12-05 MEDIUM 6.1 CVE-2012-1115 A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php. Debian Linux Mitigation only Fix from $1,6002019-12-05 MEDIUM 6.1 CVE-2012-0812 PostfixAdmin 2.3.4 has multiple XSS vulnerabilities Debian Linux Mitigation only Fix from $1,6002019-11-22 MEDIUM 6.1 CVE-2011-0544 phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag. Debian Linux after 3.0.6 Fix from $1,6002019-11-14 MEDIUM 6.1 CVE-2012-4384 letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar Debian Linux after 3.3.11 Fix from $1,6002019-11-13 MEDIUM 6.1 CVE-2009-5046 JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. Debian Linux 6.1.22+ Fix from $1,6002019-11-06 MEDIUM 6.1 CVE-2009-5049 WebApp JSP Snoop page XSS in jetty though 6.1.21. Debian Linux after 6.1.21 Fix from $1,6002019-11-06 HIGH 8.8 CVE-2013-6364 Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book Debian Linux No fix yet Fix from $1,9502019-11-05 MEDIUM 6.1 CVE-2013-4168 Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. Debian Linux Patch available Fix from $1,6002019-11-01