Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2019-05-24 CVE-2019-7092 Cross-site Scripting vulnerability in Adobe Coldfusion 11.0/2016/2018
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability.
network
adobe CWE-79
4.3
2019-05-24 CVE-2019-10685 Cross-site Scripting vulnerability in Heidelberg Prinect Archiver 2013
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
network
low complexity
heidelberg CWE-79
6.1
2019-05-24 CVE-2018-12624 Cross-site Scripting vulnerability in Eventum Project Eventum 3.5.0
An issue was discovered in Eventum 3.5.0.
4.3
2019-05-24 CVE-2019-8346 Cross-site Scripting vulnerability in Zohocorp Manageengine Adselfservice Plus
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf.
network
zohocorp CWE-79
4.3
2019-05-24 CVE-2019-11604 Cross-site Scripting vulnerability in Quest Kace Systems Management Appliance
An issue was discovered in Quest KACE Systems Management Appliance before 9.1.
network
quest CWE-79
4.3
2019-05-24 CVE-2016-10245 Cross-site Scripting vulnerability in Doxygen
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
network
doxygen CWE-79
4.3
2019-05-24 CVE-2019-12315 Cross-site Scripting vulnerability in Samsung Scx-824 Firmware
Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter.
network
samsung CWE-79
4.3
2019-05-24 CVE-2019-12195 Cross-site Scripting vulnerability in Tp-Link Tl-Wr840N Firmware 0.9.13.16
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name.
network
tp-link CWE-79
3.5
2019-05-24 CVE-2019-11876 Cross-site Scripting vulnerability in multiple products
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS.
4.3
2019-05-24 CVE-2019-12313 Cross-site Scripting vulnerability in Dollarshaveclub Shave
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
4.3