Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-07-10 CVE-2018-2435 Cross-site Scripting vulnerability in SAP Netweaver Enterprise Portal
SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2018-07-10 CVE-2018-2432 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 4.1/4.2/4.3
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user.
network
low complexity
sap CWE-79
5.4
2018-07-10 CVE-2018-2431 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 4.10/4.20
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2018-07-10 CVE-2018-13849 Cross-site Scripting vulnerability in Instagram-Clone Project Instagram-Clone 20180423
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
network
low complexity
instagram-clone-project CWE-79
6.1
2018-07-10 CVE-2018-1523 Cross-site Scripting vulnerability in IBM Rational Quality Manager
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-07-10 CVE-2018-1396 Cross-site Scripting vulnerability in IBM Rational Quality Manager
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-07-10 CVE-2017-1793 Cross-site Scripting vulnerability in IBM Rational Quality Manager
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-07-10 CVE-2017-1792 Cross-site Scripting vulnerability in IBM Rational Quality Manager
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-07-10 CVE-2017-1791 Cross-site Scripting vulnerability in IBM Rational Quality Manager
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-07-10 CVE-2017-1738 Cross-site Scripting vulnerability in IBM Rational Quality Manager
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would allow an authenticated user to obtain elevated privileges.
network
low complexity
ibm CWE-79
5.4