Total
36870 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-18087 | 1 Bixie | 1 Portfolio | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}. | |||||
CVE-2018-18082 | 1 Bijiadao | 1 Waimai Super Cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI. | |||||
CVE-2018-18069 | 1 Wpml | 1 Wpml | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php. | |||||
CVE-2018-18062 | 1 Tecrail | 1 Responsive Filemanager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2018-18035 | 1 Open-emr | 1 Openemr | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. | |||||
CVE-2018-18029 | 1 Naviwebs | 1 Navigate Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action. | |||||
CVE-2018-18019 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter. | |||||
CVE-2018-18017 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | |||||
CVE-2018-18005 | 1 Vivotek | 1 Camera | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter. | |||||
CVE-2018-17997 | 1 Layerbb | 1 Layerbb | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | |||||
CVE-2018-17989 | 1 Dlink | 2 Dsl-3782, Dsl-3782 Firmware | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested. | |||||
CVE-2018-17981 | 1 Lifesize | 4 Express 220, Express 220 Firmware, Room 220i and 1 more | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter. | |||||
CVE-2018-17964 | 1 Aryanic | 1 Highportal | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Aryanic HighPortal 12.5 has XSS via an Add Tags action. | |||||
CVE-2018-17960 | 1 Ckeditor | 1 Ckeditor | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste. | |||||
CVE-2018-17952 | 1 Microfocus | 1 Edirectory | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 | |||||
CVE-2018-17949 | 1 Microfocus | 1 Imanager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross site scripting vulnerability in iManager prior to 3.1 SP2. | |||||
CVE-2018-17947 | 1 Atmist | 1 Snazzy Maps | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter. | |||||
CVE-2018-17946 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter. | |||||
CVE-2018-17904 | 1 Geovap | 1 Reliance 4 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Reliance 4 SCADA/HMI, Version 4.7.3 Update 3 and prior. This vulnerability could allow an unauthorized attacker to inject arbitrary code. | |||||
CVE-2018-17886 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-12429. |