VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2144 CVEsRSS

CVE-2021-3184Medium· 6.1
5y ago

MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.

MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.

▾ Sunlitmisp-project · mispEPSS 0.77%via NVD
CVE-2021-25325Medium· 6.1
5y ago

MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp

MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.

▾ Sunlitmisp-project · mispEPSS 0.80%via NVD
CVE-2021-25324Medium· 6.1
5y ago

MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.

MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.

▾ Sunlitmisp-project · mispEPSS 0.80%via NVD
CVE-2020-25498Medium· 4.8PoC
5y ago

Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and "Keyword" in URL Filter.

Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and "Keyword" in URL Filter.

▾ Twilightbeetel · 777vr1_firmwareEPSS 1.1%via NVD
CVE-2020-35262Medium· 6.1PoC
5y ago

Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

▾ Twilightdigisol · dg-hr3400_firmwareEPSS 0.86%via NVD
CVE-2020-29231Medium· 5.4
5y ago

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and eac…

▾ Sunlitegavilanmedia · user_registration_and_login_system_with_admin_panelEPSS 0.60%via NVD
CVE-2020-29230Medium· 6.1
5y ago

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting…

▾ Sunlitegavilanmedia · user_registration_and_login_system_with_admin_panelEPSS 0.81%via NVD
CVE-2020-29477Medium· 4.8PoC
5y ago

Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field

Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the …

▾ Twilightinvisioncommunity · communityEPSS 1.1%via NVD
CVE-2020-29247Medium· 4.8
5y ago

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the…

▾ Sunlitwondercms · wondercmsEPSS 0.80%via NVD
CVE-2020-35275Medium· 5.4
5y ago

Coastercms v5.8.18 is affected by cross-site Scripting (XSS)

Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.

▾ Sunlitcoastercms · coastercmsEPSS 1.1%via NVD
CVE-2020-35274Medium· 4.8
5y ago

DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges

DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies us…

▾ Sunlitdotcms · dotcmsEPSS 0.62%via NVD
CVE-2020-28859Medium· 6.1
5y ago

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.

▾ Sunlitopenasset · digital_asset_managementEPSS 0.78%via NVD
CVE-2020-28857Medium· 6.1
5y ago

OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.

OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.

▾ Sunlitopenasset · digital_asset_managementEPSS 1.5%via NVD
CVE-2020-28727Medium· 6.1
5y ago

Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.

Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.

▾ Sunlitseeddms · seeddmsEPSS 0.70%via NVD
CVE-2020-29572Medium· 6.1
5y ago

app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.

app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.

▾ Sunlitmisp-project · mispEPSS 0.78%via NVD
CVE-2017-15682Medium· 6.1
5y ago

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.

▾ Sunlitcraftercms · crafter_cmsEPSS 0.75%via NVD
CVE-2020-28947Medium· 6.1
5y ago

In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.

In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.

▾ Sunlitmisp-project · mispEPSS 0.82%via NVD
CVE-2020-27193Medium· 6.1
5y ago

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.

▾ Sunlitckeditor · ckeditorEPSS 2.0%via NVD
CVE-2018-19953Medium· 6.1CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 202001…

▾ Midnightqnap · qtsEPSS 29%via NVD
CVE-2018-19943High· 8.0CISA KEV0day
5y ago

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build …

▾ Abyssalqnap · qtsEPSS 21%via NVD
CVE-2020-27388Medium· 5.4
5y ago

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS is…

▾ Sunlityourls · yourlsEPSS 0.71%via NVD
CVE-2020-3583Medium· 6.1
5y ago

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.1%via NVD
CVE-2020-3582Medium· 6.1
5y ago

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.2%via NVD
CVE-2020-3581Medium· 6.1
5y ago

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.2%via NVD
CVE-2020-3580Medium· 6.1CISA KEVPoC
5y ago

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …

▾ Midnightcisco · secure_firewall_threat_defenseEPSS 86%via NVD
CVE-2020-21733Medium· 6.1
6y ago

Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.

Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.

▾ Sunlitsagemcom · f@st_3686_firmwareEPSS 0.73%via NVD
CVE-2020-21732Medium· 6.1
6y ago

Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS)

Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.

▾ Sunlitrukovoditel · rukovoditelEPSS 0.66%via NVD
CVE-2020-21731Medium· 6.1
6y ago

Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?user_name=amministratore&Update

Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?user_name=amministratore&Update. An attacker can inject JavaScript code, and the webapplication stores the injected code.

▾ Sunlitgazie_project · gazieEPSS 0.66%via NVD
CVE-2020-24194Medium· 6.1
6y ago

A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.

A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.

▾ Sunlitdaily_tracker_system_project · daily_tracker_systemEPSS 0.83%via NVD
CVE-2020-23450Medium· 5.4
6y ago

Spiceworks Version <= 7.5.00107 is affected by XSS

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.

▾ Sunlitspiceworks · spiceworksEPSS 0.60%via NVD
CWE-79 vulnerabilities (CVEs) — page 70 · VulnSea