Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-04-12 CVE-2017-0195 Cross-site Scripting vulnerability in Microsoft products
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."
network
low complexity
microsoft CWE-79
5.4
2017-04-11 CVE-2017-7621 Cross-site Scripting vulnerability in Auromeera Emli 1.0
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt.
network
low complexity
auromeera CWE-79
6.1
2017-04-10 CVE-2016-5682 Cross-site Scripting vulnerability in Smartbear Swagger-Ui
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
network
low complexity
smartbear CWE-79
6.1
2017-04-10 CVE-2016-5642 Cross-site Scripting vulnerability in Opmantek Network Management Information System 4.3.6F/8.5.10G
Opmantek NMIS before 8.5.12G has XSS via SNMP.
network
low complexity
opmantek CWE-79
5.4
2017-04-10 CVE-2016-5078 Cross-site Scripting vulnerability in Paessler Prtg Network Monitor
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
network
low complexity
paessler CWE-79
6.1
2017-04-10 CVE-2016-5077 Cross-site Scripting vulnerability in Netikus Eventsentry 3.2.1.22/3.2.1.30/3.2.1.8
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
network
low complexity
netikus CWE-79
6.1
2017-04-10 CVE-2016-5075 Cross-site Scripting vulnerability in Cloudviewnms Cloudview NMS
CloudView NMS before 2.10a has XSS via a TELNET login.
network
low complexity
cloudviewnms CWE-79
6.1
2017-04-10 CVE-2016-5073 Cross-site Scripting vulnerability in Cloudviewnms Cloudview NMS
CloudView NMS before 2.10a has XSS via SNMP.
network
low complexity
cloudviewnms CWE-79
6.1
2017-04-10 CVE-2016-5055 Cross-site Scripting vulnerability in Osram Lightify PRO
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
network
low complexity
osram CWE-79
6.1
2017-04-10 CVE-2016-4318 Cross-site Scripting vulnerability in Atlassian Jira
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
network
low complexity
atlassian CWE-79
4.8