Total
35377 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-16555 | 1 Siemens | 8 Scalance S602, Scalance S602 Firmware, Scalance S612 and 5 more | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known. | |||||
CVE-2018-16551 | 1 Lavalite | 1 Lavalite | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit. | |||||
CVE-2018-16519 | 1 Coyoapp | 1 Coyo | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets. | |||||
CVE-2018-16516 | 1 Flask-admin Project | 1 Flask-admin | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL. | |||||
CVE-2018-16514 | 1 Mantisbt | 1 Mantisbt | 2024-11-21 | 2.6 LOW | 4.7 MEDIUM |
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055. | |||||
CVE-2018-16484 | 1 M-server Project | 1 M-server | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names. | |||||
CVE-2018-16481 | 1 Html-pages Project | 1 Html-pages | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering. | |||||
CVE-2018-16480 | 1 Public Project | 1 Public | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering. | |||||
CVE-2018-16474 | 1 Tianma-static Project | 1 Tianma-static | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript. | |||||
CVE-2018-16471 | 2 Debian, Rack Project | 2 Debian Linux, Rack | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable. | |||||
CVE-2018-16468 | 2 Debian, Loofah Project | 2 Debian Linux, Loofah | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. | |||||
CVE-2018-16459 | 1 Exceljs Project | 1 Exceljs | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser. | |||||
CVE-2018-16456 | 1 Phpscriptsmall | 1 Website Seller Script | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature. | |||||
CVE-2018-16455 | 1 Marketplace Script Project | 1 Marketplace Script | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword. | |||||
CVE-2018-16453 | 1 Domain Lookup Script Project | 1 Domain Lookup Script | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Domain Lookup Script 3.0.5 allows XSS in the search bar. | |||||
CVE-2018-16450 | 1 Craftedweb Project | 1 Craftedweb | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter. | |||||
CVE-2018-16407 | 1 Mayan-edms | 1 Mayan Edms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. | |||||
CVE-2018-16406 | 1 Mayan-edms | 1 Mayan Edms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. | |||||
CVE-2018-16405 | 1 Mayan-edms | 1 Mayan Edms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. | |||||
CVE-2018-16381 | 1 E107 | 1 E107 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter. |