Vulnerabilities (CVE)

Filtered by CWE-79
Total 37646 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-10041 1 Siemens 6 Sicam Mmu, Sicam Mmu Firmware, Sicam Sgu and 3 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A stored Cross-Site-Scripting (XSS) vulnerability is present in different locations of the web application. An attacker might be able to take over a session of a legitimate user.
CVE-2020-10012 1 Apple 2 Mac Os X, Macos 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.
CVE-2020-0872 1 Microsoft 1 Application Inspector 2024-11-21 6.8 MEDIUM 9.6 CRITICAL
A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.
CVE-2020-0700 1 Microsoft 2 Azure Devops Server, Team Foundation Server 2024-11-21 3.5 LOW 5.4 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
CVE-2020-0656 1 Microsoft 1 Dynamics 365 2024-11-21 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
CVE-2019-9961 1 Wikindx Project 1 Wikindx 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2019-9957 1 Quadbase 1 Espressreport Es 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The XSS payload is stored by creating a new user account, and setting the username to an XSS payload. The stored payload can then be triggered by accessing the "Set Security Levels" or "View User/Group Relationships" page. If the attacker does not currently have permission to create a new user, another vulnerability such as CSRF must be exploited first.
CVE-2019-9955 1 Zyxel 42 Atp200, Atp200 Firmware, Atp500 and 39 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
CVE-2019-9925 1 S-cms 1 S-cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
CVE-2019-9919 1 Harmistechnology 1 Je Messenger 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.
CVE-2019-9914 1 Yop-poll 1 Yop-poll 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
CVE-2019-9913 1 3cx 1 Live Chat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
CVE-2019-9912 1 Codecabin 1 Wp Go Maps 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
CVE-2019-9911 1 Nextscripts 1 Social Networks Auto Poster 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
CVE-2019-9910 1 King-theme 1 Kingcomposer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
CVE-2019-9909 1 Givewp 1 Givewp 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
CVE-2019-9908 1 Hivewebstudios 1 Font Organizer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
CVE-2019-9844 2 Fedoraproject, Khanacademy 2 Fedora, Simple-markdown 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
CVE-2019-9841 1 Vestacp 1 Control Panel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
CVE-2019-9839 1 Vfront 1 Vfront 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.