Vulnerability index

Browse CVEs

104 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Keycloak MEDIUM 6.1
CVE-2020-10748

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows a…

Fix: 7.4.1+
Fix from $1,600 2020-09-16
Cloudforms MEDIUM 5.4
CVE-2020-10777

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS…

Mitigation only
Fix from $1,600 2020-08-11
Quay MEDIUM 6.1
CVE-2019-3865

A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use th…

Mitigation only
Fix from $1,600 2020-06-22
Interchange MEDIUM 6.1
CVE-2020-12685

XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentia…

Fix: 5.12.0+
Fix from $1,600 2020-05-15
Ceph Storage MEDIUM 6.1
CVE-2020-1760

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS …

Fix: 14.2.21+
Fix from $1,600 2020-04-23
Certificate System MEDIUM 5.4
CVE-2020-1696

A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a…

Fix: after 10.8.3
Fix from $1,600 2020-03-20
Enterprise Linux MEDIUM 6.1
CVE-2019-10179

A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery re…

Fix: after 10.8.3
Fix from $1,600 2020-03-20
Enterprise Linux MEDIUM 6.1
CVE-2019-10221

A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw…

Fix: after 10.8.3
Fix from $1,600 2020-03-20
Virtualization MEDIUM 6.1
CVE-2019-19336

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were includ…

Fix: 4.3.8+
Fix from $1,600 2020-03-19
Keycloak MEDIUM 5.4
CVE-2020-1697

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated pro…

Fix: 9.0.0+
Fix from $1,600 2020-02-10
Subscription Asset Manager MEDIUM 6.1
CVE-2014-0183

Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.

Mitigation only
Fix from $1,600 2020-01-02
Decision Manager MEDIUM 6.1
CVE-2019-14862

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers…

Fix: after 3.4.2
Fix from $1,600 2020-01-02
Decision Manager MEDIUM 6.1
CVE-2019-14863

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application de…

Fix: after 1.4.14
Fix from $1,600 2020-01-02
Jboss Fuse MEDIUM 6.1
CVE-2016-1000229

swagger-ui has XSS in key names

Mitigation only
Fix from $1,600 2019-12-20
3scale MEDIUM 5.4
CVE-2019-14849

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to …

Fix: 2.6+
Fix from $1,600 2019-12-12
Jboss Enterprise Application Platform MEDIUM 6.1
CVE-2013-6495

JBossWeb Bayeux has reflected XSS

Fix: 6.1.0 / 6.1.1+
Fix from $1,600 2019-12-11
Openshift MEDIUM 6.1
CVE-2013-7370

node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware

Fix: 2.8.1+
Fix from $1,600 2019-12-11
Jboss Keycloak MEDIUM 6.1
CVE-2014-3656

JBoss KeyCloak: XSS in login-status-iframe.html

No fix yet
Fix from $1,600 2019-12-10
Satellite MEDIUM 5.4
CVE-2013-2101

Katello has multiple XSS issues in various entities

No fix yet
Fix from $1,600 2019-12-03
Jboss Application Server MEDIUM 5.4
CVE-2011-3606

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could…

Mitigation only
Fix from $1,600 2019-11-26
Cloudforms Management Engine MEDIUM 5.4
CVE-2018-10854

cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure m…

Mitigation only
Fix from $1,600 2019-11-22
Openshift Origin MEDIUM 6.1
CVE-2014-3592

OpenShift Origin: Improperly validated team names could allow stored XSS attacks

Fix: after 2014-08-13
Fix from $1,600 2019-11-13
Jboss Business Rules Management System MEDIUM 6.1
CVE-2010-3857

JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.

Fix: 5.1.0+
Fix from $1,600 2019-11-12
Hibernate Validator MEDIUM 6.1
CVE-2019-10219

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially mal…

Fix: 6.0.18+
Fix from $1,600 2019-11-08
Pagure MEDIUM 6.1
CVE-2016-1000037

Pagure: XSS possible in file attachment endpoint

Fix: 2.3.4+
Fix from $1,600 2019-11-06
Jboss Aerogear MEDIUM 6.1
CVE-2014-3649

JBoss AeroGear has reflected XSS via the password field

Fix: after 2014-09-19
Fix from $1,600 2019-11-04
Cloudforms MEDIUM 6.1
CVE-2013-0186

Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

Mitigation only
Fix from $1,600 2019-11-01
Tectonic MEDIUM 6.1
CVE-2018-9090

CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administr…

Fix: 1.8.7-tectonic.2+
Fix from $1,600 2019-09-24
Openshift Container Platform MEDIUM 5.4
CVE-2019-3889

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 thr…

Fix: after 3.11
Fix from $1,600 2019-07-11
Cloudforms Management Engine MEDIUM 6.5
CVE-2019-10177

A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no…

Mitigation only
Fix from $1,600 2019-06-27