Vulnerabilities (CVE)

Filtered by CWE-79
Total 38037 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4195 1 Firmanet 1 Customer Relation Manager 2024-11-21 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows XSS Targeting HTML Attributes.This issue affects Customer Relation Manager: before 2022.03.13.
CVE-2021-4179 1 Livehelperchat 1 Live Helper Chat 2024-11-21 3.5 LOW 5.4 MEDIUM
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4176 1 Livehelperchat 1 Live Helper Chat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4175 1 Livehelperchat 1 Live Helper Chat 2024-11-21 3.5 LOW 5.4 MEDIUM
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4172 1 Showdoc 1 Showdoc 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2021-4170 1 Janeczku 1 Calibre-web 2024-11-21 3.5 LOW 5.4 MEDIUM
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4169 1 Livehelperchat 1 Live Helper Chat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4143 1 Bigbluebutton 1 Bigbluebutton 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
CVE-2021-4139 1 Pimcore 1 Pimcore 2024-11-21 6.0 MEDIUM 9.0 CRITICAL
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4132 1 Livehelperchat 1 Live Helper Chat 2024-11-21 3.5 LOW 5.4 MEDIUM
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4124 1 Meetecho 1 Janus 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4121 1 Yetiforce 1 Yetiforce Customer Relationship Management 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4116 1 Yetiforce 1 Yetiforce Customer Relationship Management 2024-11-21 3.5 LOW 5.4 MEDIUM
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4108 1 Snipeitapp 1 Snipe-it 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4107 1 Yetiforce 1 Yetiforce Customer Relationship Management 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4103 1 B3log 1 Vditor 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
CVE-2021-4084 1 Pimcore 1 Pimcore 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4081 1 Pimcore 1 Pimcore 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4074 1 I-plugins 1 Whmcs Bridge 2024-11-21 3.5 LOW 6.4 MEDIUM
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_admin function, low-level authenticated users such as subscribers can exploit this vulnerability.
CVE-2021-4072 1 Elgg 1 Elgg 2024-11-21 3.5 LOW 5.4 MEDIUM
elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')