Total
38009 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-3529 | 1 Redhat | 2 Noobaa-operator, Openshift Container Platform | 2024-11-21 | 6.8 MEDIUM | 7.1 HIGH |
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity. | |||||
CVE-2021-3509 | 1 Redhat | 1 Ceph Storage | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to the system is for confidentiality, integrity, and availability. | |||||
CVE-2021-3486 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code. | |||||
CVE-2021-3441 | 1 Hp | 2 Officejet 7110, Officejet 7110 Firmware | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS). | |||||
CVE-2021-3427 | 1 Deluge-torrent | 1 Deluge | 2024-11-21 | N/A | 6.1 MEDIUM |
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session. | |||||
CVE-2021-3395 | 1 Pryaniki | 1 Pryaniki | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment. | |||||
CVE-2021-3377 | 1 Ansi Up Project | 1 Ansi Up | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0. | |||||
CVE-2021-3370 | 1 Douco | 1 Douphp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. | |||||
CVE-2021-3355 | 1 Lightcms Project | 1 Lightcms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords. | |||||
CVE-2021-3351 | 1 Openplcproject | 1 Openplc | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page. | |||||
CVE-2021-3350 | 1 Delete Account Project | 1 Delete Account | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter. | |||||
CVE-2021-3340 | 1 Wikindx Project | 1 Wikindx | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php?action=initLogon or modules/admin/DELETEIMAGES.php. | |||||
CVE-2021-3333 | 1 Opmantek | 1 Open-audit | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link. | |||||
CVE-2021-3327 | 1 Ovation | 1 Dynamic Content | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. | |||||
CVE-2021-3318 | 1 Dzzoffice | 1 Dzzoffice | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. | |||||
CVE-2021-3315 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. | |||||
CVE-2021-3314 | 1 Oracle | 1 Glassfish Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |||||
CVE-2021-3313 | 1 Plone | 1 Plone | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript in the context of the victim's browser if the victim opens a vulnerable page containing an XSS payload. | |||||
CVE-2021-3298 | 1 O-dyn | 1 Collabtive | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter. | |||||
CVE-2021-3294 | 1 Casap Automated Enrollment System Project | 1 Casap Automated Enrollment System | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website. |