Vulnerabilities (CVE)

Filtered by CWE-79
Total 36832 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4170 1 Emberjs 1 Ember.js 2024-11-21 2.6 LOW 6.1 MEDIUM
In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into such a string without being sanitized. This means that if an application assigns a view's `tagName` to user-supplied data, a specially-crafted payload could execute arbitrary JavaScript in the context of the current domain ("XSS"). This vulnerability only affects applications that assign or bind user-provided content to `tagName`.
CVE-2013-4168 3 Debian, Fedoraproject, Smokeping 3 Debian Linux, Fedora, Smokeping 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
CVE-2013-4158 3 Debian, Fedoraproject, Smokeping 3 Debian Linux, Fedora, Smokeping 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
CVE-2013-4109 1 Cryptocat Project 1 Cryptocat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
CVE-2013-4107 1 Cryptocat Project 1 Cryptocat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
CVE-2013-4106 1 Cryptocat Project 1 Cryptocat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
CVE-2013-3936 1 Opsview 2 Opsview, Opsview Core 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.
CVE-2013-3931 1 Jomres 1 Jomres 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to inject arbitrary web script or HTML via the property_name parameter, related to editing property details.
CVE-2013-3637 1 Projectpier 1 Projectpier 2024-11-21 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 does not use the Secure flag for cookies
CVE-2013-3636 1 Projectpier 1 Projectpier 2024-11-21 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
CVE-2013-3635 1 Projectpier 1 Projectpier 2024-11-21 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 has stored XSS
CVE-2013-3565 2 Opensuse, Videolan 2 Opensuse, Vlc Media Player 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.
CVE-2013-3517 1 Netgear 4 Wnr3500l, Wnr3500l Firmware, Wnr3500u and 1 more 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
CVE-2013-3320 1 Netapp 1 Oncommand System Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.
CVE-2013-3097 1 Actiontec 2 Mi424wr-gen3i, Mi424wr-gen3i Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
CVE-2013-3067 1 Linksys 2 Wrt310n, Wrt310n Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
CVE-2013-2999 1 Ibm 1 Infosphere Data Replication Dashboard 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115.
CVE-2013-2714 1 Podpress Project 1 Podpress 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
CVE-2013-2684 1 Cisco 2 Linksys E4200, Linksys E4200 Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-2679 1 Belkin 2 Linksys E4200, Linksys E4200 Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.