Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-35200 Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35201 Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35202 Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35199 Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. Openfire No fix yet Fix from $1,6002020-12-12 MEDIUM 5.4 CVE-2020-35127 Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. Openfire No fix yet Fix from $1,6002020-12-11 MEDIUM 6.1 CVE-2020-24601 In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST … Openfire No fix yet Fix from $1,6002020-09-02 MEDIUM 6.1 CVE-2020-24602 Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the… Openfire No fix yet Fix from $1,6002020-09-02 MEDIUM 6.1 CVE-2020-24604 A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbit… Openfire No fix yet Fix from $1,6002020-09-02 HIGH 8.8 CVE-2020-12772 An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC … Spark No fix yet Fix from $1,9502020-05-12 MEDIUM 6.1 CVE-2019-20525 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. Openfire No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20526 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. Openfire No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20527 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. Openfire No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2019-20528 Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. Openfire No fix yet Fix from $1,6002020-03-18 HIGH 8.1 CVE-2017-2815 An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the r… User Import Export Mitigation only Fix from $1,9502018-05-15 MEDIUM 6.5 CVE-2015-7707EPSS 6% Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. Openfire No fix yet Fix from $1,6002015-10-05 MEDIUM 6.8 CVE-2015-6973EPSS 65% Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of … Openfire No fix yet Fix from $1,6002015-09-16 MEDIUM 5.0 CVE-2009-0497EPSS 8% Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot bac… Openfire No fix yet Fix from $1,6002009-02-10