Vulnerabilities (CVE)

Filtered by CWE-79
Total 37840 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-33666 1 Sap 1 Commerce Cloud 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.
CVE-2021-33665 1 Sap 1 Netweaver Application Server Abap 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2021-33664 1 Sap 1 Netweaver Application Server Abap 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2021-33618 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
CVE-2021-33616 1 Rsa 1 Archer 2024-11-21 3.5 LOW 5.4 MEDIUM
RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.
CVE-2021-33611 1 Vaadin 2 Vaadin, Vaadin-menu-bar 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL
CVE-2021-33570 1 Postbird Project 1 Postbird 2024-11-21 3.5 LOW 5.4 MEDIUM
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
CVE-2021-33562 1 Shopizer 1 Shopizer 2024-11-21 3.5 LOW 4.8 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.
CVE-2021-33561 1 Shopizer 1 Shopizer 2024-11-21 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.
CVE-2021-33557 1 Mantisbt 1 Mantisbt 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.
CVE-2021-33513 1 Plone 1 Plone 2024-11-21 3.5 LOW 5.4 MEDIUM
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
CVE-2021-33512 1 Plone 1 Plone 2024-11-21 3.5 LOW 5.4 MEDIUM
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
CVE-2021-33508 1 Plone 1 Plone 2024-11-21 3.5 LOW 5.4 MEDIUM
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
CVE-2021-33507 2 Plone, Zope 2 Plone, Zope 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
CVE-2021-33501 1 Overwolf 1 Overwolf 2024-11-21 9.3 HIGH 9.6 CRITICAL
Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CVE-2021-33496 1 Dutchcoders 1 Transfer.sh 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view.
CVE-2021-33495 1 Open-xchange 1 Ox App Suite 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
CVE-2021-33494 1 Open-xchange 1 Ox App Suite 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
CVE-2021-33492 1 Open-xchange 1 Ox App Suite 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OX App Suite 7.10.5 allows XSS via an OX Chat room name.
CVE-2021-33490 1 Open-xchange 1 Ox App Suite 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.