Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2020-10748
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows a…
Keycloak
7.4.1+
MEDIUM 5.4
CVE-2020-10777
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS…
Cloudforms
Mitigation only
MEDIUM 6.1
CVE-2019-3865
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use th…
Quay
Mitigation only
MEDIUM 6.1
CVE-2020-12685
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentia…
Interchange
5.12.0+
MEDIUM 6.1
CVE-2020-1760
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS …
Ceph Storage
14.2.21+
MEDIUM 5.4
CVE-2020-1696
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a…
Certificate System
after 10.8.3
MEDIUM 6.1
CVE-2019-10179
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery re…
Enterprise Linux
after 10.8.3
MEDIUM 6.1
CVE-2019-10221
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw…
Enterprise Linux
after 10.8.3
MEDIUM 6.1
CVE-2019-19336
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were includ…
Virtualization
4.3.8+
MEDIUM 5.4
CVE-2020-1697
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated pro…
Keycloak
9.0.0+
MEDIUM 6.1
CVE-2014-0183
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
Subscription Asset Manager
Mitigation only
MEDIUM 6.1
CVE-2019-14862
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers…
Decision Manager
after 3.4.2
MEDIUM 6.1
CVE-2019-14863
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application de…
Decision Manager
after 1.4.14
MEDIUM 6.1
CVE-2016-1000229
swagger-ui has XSS in key names
Jboss Fuse
Mitigation only
MEDIUM 5.4
CVE-2019-14849
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to …
3scale
2.6+
MEDIUM 6.1
CVE-2013-6495
JBossWeb Bayeux has reflected XSS
Jboss Enterprise Application Platform
6.1.0 / 6.1.1+
MEDIUM 6.1
CVE-2013-7370
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
Openshift
2.8.1+
MEDIUM 6.1
CVE-2014-3656
JBoss KeyCloak: XSS in login-status-iframe.html
Jboss Keycloak
No fix yet
MEDIUM 5.4
CVE-2013-2101
Katello has multiple XSS issues in various entities
Satellite
No fix yet
MEDIUM 5.4
CVE-2011-3606
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could…
Jboss Application Server
Mitigation only
MEDIUM 5.4
CVE-2018-10854
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure m…
Cloudforms Management Engine
Mitigation only
MEDIUM 6.1
CVE-2014-3592
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
Openshift Origin
after 2014-08-13
MEDIUM 6.1
CVE-2010-3857
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
Jboss Business Rules Management System
5.1.0+
MEDIUM 6.1
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially mal…
Hibernate Validator
6.0.18+
MEDIUM 6.1
CVE-2016-1000037
Pagure: XSS possible in file attachment endpoint
Pagure
2.3.4+
MEDIUM 6.1
CVE-2014-3649
JBoss AeroGear has reflected XSS via the password field
Jboss Aerogear
after 2014-09-19
MEDIUM 6.1
CVE-2013-0186
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
Cloudforms
Mitigation only
MEDIUM 6.1
CVE-2018-9090
CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administr…
Tectonic
1.8.7-tectonic.2+
MEDIUM 5.4
CVE-2019-3889
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 thr…
Openshift Container Platform
after 3.11
MEDIUM 6.5
CVE-2019-10177
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no…
Cloudforms Management Engine
Mitigation only