Vulnerability index

Browse CVEs

1,094 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 5.4 CVE-2016-9979 IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS… Curam Social Program Management Patch available Fix from $1,6002017-04-20 MEDIUM 5.4 CVE-2016-9980 IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS… Curam Social Program Management Patch available Fix from $1,6002017-04-20 MEDIUM 5.4 CVE-2016-3038 IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI … Cognos Business Intelligence Patch available Fix from $1,6002017-04-17 MEDIUM 5.4 CVE-2017-1160 IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users … Financial Transaction Manager Patch available Fix from $1,6002017-04-17 MEDIUM 5.4 CVE-2016-8927 IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb… Tivoli Application Dependency Discovery Manager Patch available Fix from $1,6002017-04-14 MEDIUM 5.4 CVE-2016-3015 IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Cognos Analytics Patch available Fix from $1,6002017-04-05 MEDIUM 5.4 CVE-2016-3031 IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… Cognos Analytics Patch available Fix from $1,6002017-04-05 MEDIUM 6.1 CVE-2016-9990 IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a… Inotes Patch available Fix from $1,6002017-03-31 MEDIUM 5.4 CVE-2016-6022 IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod… Rational Quality Manager Patch available Fix from $1,6002017-03-31 MEDIUM 5.4 CVE-2016-6031 IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript … Rational Quality Manager Patch available Fix from $1,6002017-03-31 MEDIUM 5.4 CVE-2016-6036 IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS… Rational Quality Manager Patch available Fix from $1,6002017-03-31 MEDIUM 5.4 CVE-2016-8935 IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embe… Kenexa Lms Patch available Fix from $1,6002017-03-31 MEDIUM 6.1 CVE-2017-1120 IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web… Websphere Portal Patch available Fix from $1,6002017-03-27 MEDIUM 5.4 CVE-2016-6056 IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in… Call Center For Commerce Patch available Fix from $1,6002017-03-27 MEDIUM 5.4 CVE-2016-9737 IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI… Tririga Application Platform Patch available Fix from $1,6002017-03-27 MEDIUM 5.4 CVE-2016-9694 IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We… Rational Rhapsody Design Manager Patch available Fix from $1,6002017-03-20 MEDIUM 5.4 CVE-2016-9696 IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be ex… Rational Rhapsody Design Manager Patch available Fix from $1,6002017-03-20 MEDIUM 5.4 CVE-2017-1146 IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Content Navigator Mitigation only Fix from $1,6002017-03-20 MEDIUM 5.4 CVE-2016-9006 IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web… Urbancode Deploy Mitigation only Fix from $1,6002017-03-08 MEDIUM 6.1 CVE-2016-9723 IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering … Qradar Incident Forensics Patch available Fix from $1,6002017-03-07 MEDIUM 5.4 CVE-2017-1133 IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering … Qradar Incident Forensics Patch available Fix from $1,6002017-03-07 MEDIUM 6.1 CVE-2016-8232 Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM … Advanced Management Module Firmware Mitigation only Fix from $1,6002017-03-01 MEDIUM 5.4 CVE-2016-5932 IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t… Connections Mitigation only Fix from $1,6002017-03-01 MEDIUM 6.1 CVE-2016-5883 IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a… Inotes Patch available Fix from $1,6002017-02-23 MEDIUM 5.4 CVE-2016-6055 IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc… Rational Doors Next Generation Patch available Fix from $1,6002017-02-23 MEDIUM 6.1 CVE-2016-6062 IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th… Resilient Mitigation only Fix from $1,6002017-02-16 MEDIUM 5.4 CVE-2016-8968 IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte… Rational Collaborative Lifecycle Management Patch available Fix from $1,6002017-02-15 MEDIUM 5.4 CVE-2017-1121 IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri… Websphere Application Server Patch available Fix from $1,6002017-02-13 MEDIUM 6.1 CVE-2016-5902 IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t… Maximo Asset Management Patch available Fix from $1,6002017-02-08 MEDIUM 5.4 CVE-2016-0305 IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vul… Connections Patch available Fix from $1,6002017-02-08