Total
37815 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-27888 | 1 Zend | 1 Zendto | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters. | |||||
CVE-2021-27887 | 1 Hitachiabb-powergrids | 1 Ellipse Asset Performance Management | 2024-11-21 | 3.5 LOW | 6.3 MEDIUM |
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions. | |||||
CVE-2021-27822 | 1 Phpgurukul | 1 Vehicle Parking Management System | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field. | |||||
CVE-2021-27821 | 1 Openwrt | 1 Luci | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability which can lead to attackers carrying out arbitrary code execution. | |||||
CVE-2021-27781 | 1 Hcltech | 2 Bigfix Mobile, Modern Client Management | 2024-11-21 | 3.5 LOW | 6.6 MEDIUM |
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. | |||||
CVE-2021-27778 | 1 Hcltech | 1 Traveler | 2024-11-21 | 3.5 LOW | 4.9 MEDIUM |
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site. | |||||
CVE-2021-27746 | 1 Hcltechsw | 1 Connections | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability" | |||||
CVE-2021-27733 | 1 Jetbrains | 1 Youtrack | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. | |||||
CVE-2021-27731 | 1 Accellion | 1 Fta | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later. | |||||
CVE-2021-27695 | 1 Openmaint | 1 Openmaint | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters. | |||||
CVE-2021-27679 | 1 Batflat | 1 Batflat | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name. | |||||
CVE-2021-27678 | 1 Batflat | 1 Batflat | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name. | |||||
CVE-2021-27677 | 1 Batflat | 1 Batflat | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name. | |||||
CVE-2021-27676 | 1 Centreon | 1 Centreon | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page. | |||||
CVE-2021-27673 | 1 Tribalsystems | 1 Zenario | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "cID" parameter when creating a new HTML component. | |||||
CVE-2021-27671 | 1 Comrak Project | 1 Comrak | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the comrak crate before 0.9.1 for Rust. XSS can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack. | |||||
CVE-2021-27659 | 1 Johnsoncontrols | 1 Exacqvision Web Service | 2024-11-21 | 4.3 MEDIUM | 5.3 MEDIUM |
exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users. | |||||
CVE-2021-27658 | 1 Johnsoncontrols | 1 Exacqvision Enterprise Manager | 2024-11-21 | 3.5 LOW | 4.3 MEDIUM |
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users. | |||||
CVE-2021-27615 | 1 Sap | 1 Manufacturing Execution | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTTP response. The lack of these headers in response can be exploited by the attacker to execute Cross-Site Scripting (XSS) attacks. | |||||
CVE-2021-27601 | 1 Sap | 1 Netweaver Application Server Java | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree. |