Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-03-28 CVE-2016-9454 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9130 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9128 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9126 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-27 CVE-2017-1120 Cross-site Scripting vulnerability in IBM Websphere Portal 8.5/9.0
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-03-27 CVE-2016-9737 Cross-site Scripting vulnerability in IBM Tririga Application Platform
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-27 CVE-2016-6056 Cross-site Scripting vulnerability in IBM Call Center for Commerce 9.3/9.4
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-27 CVE-2017-7271 Cross-site Scripting vulnerability in YII Software YII 2.0.10
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.
network
low complexity
yii-software CWE-79
6.1
2017-03-27 CVE-2015-8010 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.
network
low complexity
icinga opensuse-project opensuse CWE-79
6.1
2017-03-27 CVE-2017-6878 Cross-site Scripting vulnerability in Metinfo 5.3.15
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.
network
low complexity
metinfo CWE-79
5.4