Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2019-05-16 CVE-2019-10913 Cross-site Scripting vulnerability in Sensiolabs Symfony
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS.
network
low complexity
sensiolabs CWE-79
7.5
2019-05-16 CVE-2019-10909 Cross-site Scripting vulnerability in multiple products
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included.
3.5
2019-05-16 CVE-2019-0979 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
3.5
2019-05-16 CVE-2019-0963 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation 2013
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
microsoft CWE-79
3.5
2019-05-16 CVE-2019-0958 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
network
low complexity
microsoft CWE-79
6.5
2019-05-16 CVE-2019-0951 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation 2010/2013
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
microsoft CWE-79
3.5
2019-05-16 CVE-2019-0950 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
microsoft CWE-79
3.5
2019-05-16 CVE-2019-0949 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
microsoft CWE-79
3.5
2019-05-16 CVE-2019-0872 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
3.5
2019-05-16 CVE-2019-12139 Cross-site Scripting vulnerability in EZ Ezplatform-Admin-Ui and Ezplatform-Page-Builder
An XSS issue was discovered in the Admin UI in eZ Platform 2.x.
network
ez CWE-79
4.3