Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-03-05 CVE-2018-7663 Cross-site Scripting vulnerability in Voten
An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25.
network
low complexity
voten CWE-79
6.1
2018-03-04 CVE-2018-7653 Cross-site Scripting vulnerability in Yzmcms 3.6
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
network
low complexity
yzmcms CWE-79
6.1
2018-03-04 CVE-2018-7652 Cross-site Scripting vulnerability in Zonemaster web GUI
lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.
network
low complexity
zonemaster CWE-79
6.1
2018-03-02 CVE-2017-9276 Cross-site Scripting vulnerability in Netiq Access Manager
Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.
network
low complexity
netiq CWE-79
6.1
2018-03-02 CVE-2017-7438 Cross-site Scripting vulnerability in Netiq Privileged Account Manager 3.1
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.
network
low complexity
netiq CWE-79
6.1
2018-03-02 CVE-2017-7419 Cross-site Scripting vulnerability in Netiq Access Manager 4.2/4.3
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.
network
low complexity
netiq CWE-79
6.1
2018-03-02 CVE-2017-14801 Cross-site Scripting vulnerability in Netiq Access Manager
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
network
low complexity
netiq CWE-79
6.1
2018-03-01 CVE-2017-6929 Cross-site Scripting vulnerability in multiple products
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains.
network
low complexity
drupal debian CWE-79
6.1
2018-03-01 CVE-2017-6927 Cross-site Scripting vulnerability in multiple products
Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping).
network
low complexity
drupal debian CWE-79
6.1
2018-03-01 CVE-2018-7049 Cross-site Scripting vulnerability in Wowza Streaming Engine
An issue was discovered in Wowza Streaming Engine before 4.7.1.
network
low complexity
wowza CWE-79
6.1