Total
35377 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-14971 | 1 Q-cms | 1 Qcms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS. | |||||
CVE-2018-14970 | 1 Q-cms | 1 Qcms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS. | |||||
CVE-2018-14969 | 1 Q-cms | 1 Qcms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS. | |||||
CVE-2018-14964 | 1 Emlsoft Project | 1 Emlsoft | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page. | |||||
CVE-2018-14962 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php. | |||||
CVE-2018-14955 | 1 Squirrelmail | 1 Squirrelmail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute). | |||||
CVE-2018-14954 | 1 Squirrelmail | 1 Squirrelmail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute. | |||||
CVE-2018-14953 | 1 Squirrelmail | 1 Squirrelmail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. | |||||
CVE-2018-14952 | 1 Squirrelmail | 1 Squirrelmail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack. | |||||
CVE-2018-14951 | 1 Squirrelmail | 1 Squirrelmail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. | |||||
CVE-2018-14950 | 1 Squirrelmail | 1 Squirrelmail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack. | |||||
CVE-2018-14937 | 1 Mylittleforum | 1 My Little Forum | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field. | |||||
CVE-2018-14936 | 1 Mylittleforum | 1 My Little Forum | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Add page option in my little forum 2.4.12 allows XSS via the Title field. | |||||
CVE-2018-14935 | 1 Polycom | 2 Trio 8500, Trio 8500 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS. | |||||
CVE-2018-14929 | 1 Matera | 1 Banco | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter. | |||||
CVE-2018-14924 | 1 Matera | 1 Banco | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field. | |||||
CVE-2018-14922 | 1 Monstra | 1 Monstra | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profile page. | |||||
CVE-2018-14919 | 1 Loytec | 2 Lgate-902, Lgate-902 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
LOYTEC LGATE-902 6.3.2 devices allow XSS. | |||||
CVE-2018-14906 | 1 3cx | 1 3cx Web Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters. | |||||
CVE-2018-14905 | 1 3cx | 1 3cx Web Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter. |