Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-11-29 CVE-2018-19693 Cross-site Scripting vulnerability in Tp5Cms Project Tp5Cms 20170315/20170525
An issue was discovered in tp5cms through 2017-05-25.
network
low complexity
tp5cms-project CWE-79
6.1
2018-11-29 CVE-2018-1762 Cross-site Scripting vulnerability in IBM products
IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-11-28 CVE-2018-1584 Cross-site Scripting vulnerability in IBM Maximo Asset Management 7.6
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-11-28 CVE-2018-19630 Cross-site Scripting vulnerability in Openwrt Lede and Openwrt
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
network
low complexity
openwrt CWE-79
6.1
2018-11-27 CVE-2018-13360 Cross-site Scripting vulnerability in Terra-Master Terramaster Operating System 3.1.03
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.
network
low complexity
terra-master CWE-79
6.1
2018-11-27 CVE-2018-13359 Cross-site Scripting vulnerability in Terra-Master Terramaster Operating System 3.1.03
Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.
network
low complexity
terra-master CWE-79
8.8
2018-11-27 CVE-2018-13357 Cross-site Scripting vulnerability in Terra-Master Terramaster Operating System 3.1.03
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names.
network
low complexity
terra-master CWE-79
5.4
2018-11-27 CVE-2018-13351 Cross-site Scripting vulnerability in Terra-Master Terramaster Operating System 3.1.03
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the edit password form.
network
low complexity
terra-master CWE-79
4.8
2018-11-27 CVE-2018-13349 Cross-site Scripting vulnerability in Terra-Master Terramaster Operating System 3.1.03
Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username.
network
low complexity
terra-master CWE-79
6.1
2018-11-27 CVE-2018-13335 Cross-site Scripting vulnerability in Terra-Master Terramaster Operating System 3.1.03
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing shared folders via their descriptions.
network
low complexity
terra-master CWE-79
5.4