Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.0
CVE-2019-3873
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2019-3872
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. …
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2018-10934
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2018-16887
A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locati…
Satellite
3.9.0+
MEDIUM 6.1
CVE-2017-1002152
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
Bodhi
after 2.9.0
MEDIUM 5.4
CVE-2018-14655
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip…
Keycloak
Mitigation only
MEDIUM 5.4
CVE-2016-6343
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access da…
Jboss Bpm Suite
6.4.2+
MEDIUM 5.4
CVE-2018-10937
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods…
Openshift Container Platform
Patch available
MEDIUM 5.4
CVE-2016-8608
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remo…
Jboss Bpm Suite
Mitigation only
MEDIUM 5.4
CVE-2016-8639
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privile…
Satellite
1.13.0+
MEDIUM 5.4
CVE-2017-7514
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to spe…
Satellite
5.8.0+
MEDIUM 6.1
CVE-2017-7463
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error m…
Jboss Bpm Suite
6.4.3+
MEDIUM 5.4
CVE-2017-2674
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…
Jboss Bpm Suite
6.4.3+
MEDIUM 5.4
CVE-2017-15125
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and Ja…
Cloudforms Management Engine
5.9.0.22+
MEDIUM 5.4
CVE-2017-12175
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
Satellite
6.5+
MEDIUM 5.4
CVE-2017-7538
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organizatio…
Satellite
5.8+
MEDIUM 5.4
CVE-2017-7823
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-ori…
Enterprise Linux Desktop
52.4.0 / 56.0+
MEDIUM 6.1
CVE-2017-5466
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the rel…
Enterprise Linux
52.1.0 / 53.0+
MEDIUM 6.1
CVE-2018-11627
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Cloudforms
2.0.2+
MEDIUM 5.4
CVE-2017-7534
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, spec…
Openshift
Mitigation only
MEDIUM 5.4
CVE-2013-6465
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HT…
Jbpm
Patch available
MEDIUM 6.1
CVE-2017-15100
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "cha…
Satellite
1.16.0+
MEDIUM 5.4
CVE-2017-12158
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use …
Single Sign On
Mitigation only
MEDIUM 6.1
CVE-2014-0029
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary …
Subscription Asset Manager
Mitigation only
MEDIUM 6.1
CVE-2017-7554
It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored X…
Mobile Application Platform
Patch available
MEDIUM 5.4
CVE-2015-5181
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
Jboss A Mq
after 6.0
MEDIUM 6.1
CVE-2014-0141
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
Satellite
No fix yet
MEDIUM 6.1
CVE-2016-3113
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
Ovirt Engine
Mitigation only
MEDIUM 5.4
CVE-2016-6519
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitr…
Openstack
after 2.5
MEDIUM 6.1
CVE-2016-6347
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML …
Resteasy
Mitigation only