Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-12248 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2017-09-20 CVE-2017-14621 Cross-site Scripting vulnerability in Suse Portus 2.2.0
Portus 2.2.0 has XSS via the Team field, related to typeahead.
network
low complexity
suse CWE-79
5.4
2017-09-20 CVE-2017-14619 Cross-site Scripting vulnerability in PHPmyfaq
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.
network
low complexity
phpmyfaq CWE-79
6.1
2017-09-20 CVE-2017-14618 Cross-site Scripting vulnerability in PHPmyfaq
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
network
low complexity
phpmyfaq CWE-79
4.8
2017-09-20 CVE-2017-14615 Cross-site Scripting vulnerability in Watchguard Fireware
An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0.
network
low complexity
watchguard CWE-79
6.1
2017-09-20 CVE-2015-7347 Cross-site Scripting vulnerability in Zcms Project Zcms 1.1
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
network
low complexity
zcms-project CWE-79
4.8
2017-09-20 CVE-2015-4707 Cross-site Scripting vulnerability in Ipython
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.
network
low complexity
ipython CWE-79
6.1
2017-09-20 CVE-2015-1866 Cross-site Scripting vulnerability in Emberjs Ember.Js 1.10.0/1.11.0/1.11.1
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
network
low complexity
emberjs CWE-79
6.1
2017-09-20 CVE-2014-9758 Cross-site Scripting vulnerability in Magento 1.9.0.1
Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.
network
low complexity
magento CWE-79
6.1
2017-09-20 CVE-2015-4072 Cross-site Scripting vulnerability in Helpdesk PRO Project Helpdesk PRO
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.
network
low complexity
helpdesk-pro-project CWE-79
5.4