Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-11-14 CVE-2018-8602 Cross-site Scripting vulnerability in Microsoft Team Foundation Server 2017/2018
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team.
network
microsoft CWE-79
3.5
2018-11-14 CVE-2018-8600 Cross-site Scripting vulnerability in Microsoft Azure APP Service ON Azure Stack
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.
network
microsoft CWE-79
4.3
2018-11-14 CVE-2018-8572 Cross-site Scripting vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
network
microsoft CWE-79
3.5
2018-11-14 CVE-2018-8568 Cross-site Scripting vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
network
microsoft CWE-79
3.5
2018-11-14 CVE-2018-8547 Cross-site Scripting vulnerability in Microsoft products
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
network
microsoft CWE-79
3.5
2018-11-13 CVE-2018-16471 Cross-site Scripting vulnerability in multiple products
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11.
network
low complexity
rack-project debian CWE-79
6.1
2018-11-13 CVE-2018-2479 Cross-site Scripting vulnerability in SAP Businessobjects BI Platform 4.1/4.2
SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
sap CWE-79
4.3
2018-11-13 CVE-2018-14655 Cross-site Scripting vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final.
network
redhat CWE-79
3.5
2018-11-12 CVE-2018-19229 Cross-site Scripting vulnerability in Laobancms 2.0
An issue was discovered in LAOBANCMS 2.0.
network
laobancms CWE-79
3.5
2018-11-12 CVE-2018-19227 Cross-site Scripting vulnerability in Laobancms 2.0
An issue was discovered in LAOBANCMS 2.0.
network
laobancms CWE-79
3.5