Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2013-1951 A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web sc… Debian Linux 1.19.5 / 1.20.4+ Fix from $1,6002019-10-31 MEDIUM 5.4 CVE-2013-1934 A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote … Debian Linux after 1.2.14 Fix from $1,6002019-10-31 MEDIUM 6.1 CVE-2017-18635 An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the … Debian Linux 0.6.2+ Fix from $1,6002019-09-25 MEDIUM 6.1 CVE-2019-16728 DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari. Debian Linux 2.0.1+ Fix from $1,6002019-09-24 MEDIUM 6.1 CVE-2019-13274 In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter. Debian Linux after 4.3.28 Fix from $1,6002019-08-27 MEDIUM 6.1 CVE-2019-12471 Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perfo… Debian Linux 1.30.2 / 1.31.2+ Fix from $1,6002019-07-10 MEDIUM 6.1 CVE-2019-13345EPSS 74% The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter. Debian Linux after 4.7 Fix from $1,6002019-07-05 MEDIUM 6.1 CVE-2019-10241EPSS 10% In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES… Debian Linux after 11.7.0 Fix from $1,6002019-04-22 MEDIUM 5.4 CVE-2019-11025 In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options)… Debian Linux 1.2.3+ Fix from $1,6002019-04-08 MEDIUM 6.1 CVE-2019-10904 Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. Debian Linux No fix yet Fix from $1,6002019-04-06 MEDIUM 5.4 CVE-2018-18245 Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plu… Debian Linux No fix yet Fix from $1,6002018-12-17 MEDIUM 6.1 CVE-2018-19970 In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafte… Debian Linux 4.8.4+ Fix from $1,6002018-12-11 MEDIUM 6.1 CVE-2018-19787 An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, al… Debian Linux 4.2.5+ Fix from $1,6002018-12-02 MEDIUM 6.1 CVE-2018-16471 There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method… Debian Linux 1.6.11 / 2.0.6+ Fix from $1,6002018-11-13 MEDIUM 6.1 CVE-2018-19206EPSS 60% steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, with… Debian Linux 1.3.8+ Fix from $1,6002018-11-12 MEDIUM 5.4 CVE-2018-0618 Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via uns… Debian Linux after 2.1.26 Fix from $1,6002018-07-26 MEDIUM 6.1 CVE-2018-14040 In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. Debian Linux 3.4.0 / 4.1.2+ Fix from $1,6002018-07-13 MEDIUM 6.1 CVE-2018-1000528EPSS 46% GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password fo… Debian Linux Patch available Fix from $1,6002018-06-26 MEDIUM 5.4 CVE-2018-10060 Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.p… Debian Linux after 1.1.36 Fix from $1,6002018-04-12 MEDIUM 5.4 CVE-2018-10061 Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape funct… Debian Linux after 1.1.36 Fix from $1,6002018-04-12 MEDIUM 6.1 CVE-2018-8048 In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. Debian Linux 2.2.1+ Fix from $1,6002018-03-27 MEDIUM 6.1 CVE-2018-8763 Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or th… Debian Linux 6.3+ Fix from $1,6002018-03-27 MEDIUM 6.1 CVE-2018-1000078 RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 a… Debian Linux after 2.5.0 Fix from $1,6002018-03-13 MEDIUM 6.1 CVE-2017-18121 The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that cou… Debian Linux after 1.14.15 Fix from $1,6002018-02-02 MEDIUM 6.1 CVE-2018-5950 Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a … Debian Linux Patch available Fix from $1,6002018-01-23 MEDIUM 6.1 CVE-2017-8808 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sen… Debian Linux after 1.27.3 Fix from $1,6002017-11-15 MEDIUM 6.1 CVE-2017-15568 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a c… Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15569 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a craft… Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15570 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data. Debian Linux after 3.2.7 Fix from $1,6002017-10-18 MEDIUM 6.1 CVE-2017-15571 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data. Debian Linux after 3.2.7 Fix from $1,6002017-10-18