Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2019-03-13 CVE-2019-9736 Cross-site Scripting vulnerability in 1024Tools 1.0
DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
network
low complexity
1024tools CWE-79
6.1
2019-03-12 CVE-2019-5925 Cross-site Scripting vulnerability in Dradisframework Dradis
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
dradisframework CWE-79
5.4
2019-03-12 CVE-2019-0275 Cross-site Scripting vulnerability in SAP Netweaver Application Server Java
SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
5.4
2019-03-12 CVE-2019-0269 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 4.10/4.20
SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
5.4
2019-03-12 CVE-2019-9725 Cross-site Scripting vulnerability in Korenix products
The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field under Serial Setting.
network
low complexity
korenix CWE-79
6.1
2019-03-12 CVE-2019-9558 Cross-site Scripting vulnerability in Mailtraq Webmail 2.17.7.3550
Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message.
network
low complexity
mailtraq CWE-79
6.1
2019-03-12 CVE-2019-9557 Cross-site Scripting vulnerability in Codecrafters Ability Mail Server 4.2.6
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body.
network
low complexity
codecrafters CWE-79
6.1
2019-03-12 CVE-2019-9714 Cross-site Scripting vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.4.
network
low complexity
joomla CWE-79
6.1
2019-03-12 CVE-2019-9712 Cross-site Scripting vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.4.
network
low complexity
joomla CWE-79
6.1
2019-03-12 CVE-2019-9711 Cross-site Scripting vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.4.
network
low complexity
joomla CWE-79
6.1