Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2020-35475
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits…
Debian Linux
1.35.1+
MEDIUM 6.1
CVE-2020-35479
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, t…
Debian Linux
1.35.1+
MEDIUM 6.1
CVE-2020-25706
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template im…
Debian Linux
Patch available
MEDIUM 6.1
CVE-2020-26870
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree…
Debian Linux
2.0.17 / 21.1.0.00.01+
MEDIUM 6.1
CVE-2020-15562
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail mess…
Debian Linux
1.2.11 / 1.3.14+
MEDIUM 5.4
CVE-2020-4051
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8,…
Debian Linux
1.11.11 / 1.12.9+
MEDIUM 6.1
CVE-2020-13965 KEVEPSS 77%
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am…
Debian Linux
1.3.12 / 1.4.5+
MEDIUM 6.1
CVE-2020-11082
In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has b…
Debian Linux
1.2.1+
MEDIUM 6.1
CVE-2020-8020
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code …
Debian Linux
2020-05-13+
MEDIUM 6.1
CVE-2020-12625
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScrip…
Debian Linux
1.4.4+
MEDIUM 6.1
CVE-2020-11029
In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scriptin…
Debian Linux
3.7.33 / 3.8.33+
MEDIUM 6.1
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a…
Debian Linux
2.1.30+
MEDIUM 5.4
CVE-2020-10803
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS…
Debian Linux
4.9.5 / 5.0.2+
MEDIUM 6.1
CVE-2019-10785
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xm…
Debian Linux
1.11.9 / 1.12.7+
MEDIUM 6.1
CVE-2020-7106
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and us…
Debian Linux
1.2.9+
MEDIUM 6.1
CVE-2020-1766
Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious java…
Debian Linux
after 7.0.13
MEDIUM 6.1
CVE-2012-2237
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary we…
Debian Linux
1.4.3 / 1.5.2+
MEDIUM 6.1
CVE-2014-4913
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
Debian Linux
2.2.7 / 2.3.1+
CRITICAL 9.3
CVE-2019-18345
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied…
Debian Linux
after 1.1.8
MEDIUM 6.1
CVE-2013-7371
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
Debian Linux
2.8.2+
MEDIUM 6.1
CVE-2013-4158
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
Debian Linux
2.6.9+
MEDIUM 6.1
CVE-2012-1114
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_…
Debian Linux
Mitigation only
MEDIUM 6.1
CVE-2012-1115
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
Debian Linux
Mitigation only
MEDIUM 6.1
CVE-2012-0812
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
Debian Linux
Mitigation only
MEDIUM 6.1
CVE-2011-0544
phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
Debian Linux
after 3.0.6
MEDIUM 6.1
CVE-2012-4384
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
Debian Linux
after 3.3.11
MEDIUM 6.1
CVE-2009-5046
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
Debian Linux
6.1.22+
MEDIUM 6.1
CVE-2009-5049
WebApp JSP Snoop page XSS in jetty though 6.1.21.
Debian Linux
after 6.1.21
HIGH 8.8
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Debian Linux
No fix yet
MEDIUM 6.1
CVE-2013-4168
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
Debian Linux
Patch available