Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-07-26 CVE-2018-0618 Cross-site Scripting vulnerability in multiple products
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
gnu debian CWE-79
5.4
2018-07-26 CVE-2018-0614 Cross-site Scripting vulnerability in Necplatforms products
Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
necplatforms CWE-79
6.1
2018-07-26 CVE-2017-7538 Cross-site Scripting vulnerability in Redhat Satellite
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8.
network
low complexity
redhat CWE-79
5.4
2018-07-26 CVE-2017-7535 Cross-site Scripting vulnerability in Theforeman Foreman
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts.
network
low complexity
theforeman CWE-79
6.1
2018-07-25 CVE-2018-14493 Cross-site Scripting vulnerability in Opmantek Open-Audit 2.2.6
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.
network
low complexity
opmantek CWE-79
6.1
2018-07-25 CVE-2018-14430 Cross-site Scripting vulnerability in Mondula Multi Step Form
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
network
low complexity
mondula CWE-79
6.1
2018-07-24 CVE-2018-11059 Cross-site Scripting vulnerability in RSA Archer 6.1.0.0/6.4.0.0
RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability.
network
low complexity
rsa CWE-79
5.4
2018-07-24 CVE-2017-3180 Cross-site Scripting vulnerability in Tibco products
Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
network
low complexity
tibco CWE-79
5.4
2018-07-23 CVE-2018-8031 Cross-site Scripting vulnerability in Apache Tomee
The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL.
network
low complexity
apache CWE-79
6.1
2018-07-23 CVE-2018-1999007 Cross-site Scripting vulnerability in multiple products
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.
network
low complexity
jenkins oracle CWE-79
5.4