Vulnerabilities (CVE)

Filtered by CWE-79
Total 37897 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9734 1 Adobe 1 Experience Manager 2024-11-21 3.5 LOW 9.0 CRITICAL
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2020-9732 1 Adobe 2 Experience Manager, Experience Manager Forms 2024-11-21 6.0 MEDIUM 9.0 CRITICAL
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2020-9691 1 Magento 1 Magento 2024-11-21 9.3 HIGH 9.6 CRITICAL
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2020-9665 1 Magento 1 Magento 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-9651 1 Adobe 1 Experience Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9648 1 Adobe 1 Experience Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9647 1 Adobe 1 Experience Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9644 1 Adobe 1 Experience Manager 2024-11-21 3.5 LOW 5.4 MEDIUM
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9584 1 Magento 1 Magento 2024-11-21 3.5 LOW 5.4 MEDIUM
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-9581 1 Magento 1 Magento 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-9577 1 Magento 1 Magento 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure .
CVE-2020-9524 1 Microfocus 2 Enterprise Developer, Enterprise Server 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
CVE-2020-9522 1 Microfocus 1 Arcsight Enterprise Security Manager Express 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
CVE-2020-9520 1 Microfocus 1 Vibe 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.
CVE-2020-9496 1 Apache 1 Ofbiz 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
CVE-2020-9485 1 Apache 1 Airflow 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.
CVE-2020-9467 1 Piwigo 1 Piwigo 2024-11-21 3.5 LOW 5.4 MEDIUM
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
CVE-2020-9461 1 Octech 1 Oempro 2024-11-21 3.5 LOW 5.4 MEDIUM
Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.
CVE-2020-9460 1 Octech 1 Oempro 2024-11-21 3.5 LOW 5.4 MEDIUM
Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.
CVE-2020-9459 1 Webnus 1 Modern Events Calendar Lite 2024-11-21 3.5 LOW 5.4 MEDIUM
Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax actions. This affects mec_save_notifications and import_settings.