Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-03-23 CVE-2017-1655 Cross-site Scripting vulnerability in IBM products
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-03-23 CVE-2017-1629 Cross-site Scripting vulnerability in IBM products
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-03-23 CVE-2018-8948 Cross-site Scripting vulnerability in Misp-Project Misp
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
network
low complexity
misp-project CWE-79
6.1
2018-03-22 CVE-2018-8942 Cross-site Scripting vulnerability in Xiuno BBS Project Xiuno BBS 4.0.0
Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.
network
low complexity
xiuno-bbs-project CWE-79
5.4
2018-03-22 CVE-2018-8903 Cross-site Scripting vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
network
low complexity
open-audit CWE-79
5.4
2018-03-22 CVE-2018-7512 Cross-site Scripting vulnerability in Geutebrueck G-Cam/Efd-2250 Firmware and Topfd-2125 Firmware
A cross-site scripting vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.
network
low complexity
geutebrueck CWE-79
6.1
2018-03-22 CVE-2017-16771 Cross-site Scripting vulnerability in Synology Photo Station
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
network
low complexity
synology CWE-79
6.1
2018-03-22 CVE-2018-0538 Cross-site Scripting vulnerability in QQQ Systems Project QQQ Systems 2.24
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
qqq-systems-project CWE-79
6.1
2018-03-22 CVE-2018-0537 Cross-site Scripting vulnerability in QQQ Systems Project QQQ Systems 2.24
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz_op.cgi.
network
low complexity
qqq-systems-project CWE-79
6.1
2018-03-22 CVE-2018-0536 Cross-site Scripting vulnerability in QQQ Systems Project QQQ Systems 2.24
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz.cgi.
network
low complexity
qqq-systems-project CWE-79
6.1