Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-07-12 | CVE-2017-7678 | Cross-site Scripting vulnerability in Apache Spark In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to the Spark master, or history server. | 6.1 |
2017-07-12 | CVE-2017-11182 | Cross-site Scripting vulnerability in Fairsketch Rise Ultimate Project Manager 1.8 In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. | 5.4 |
2017-07-12 | CVE-2017-11181 | Cross-site Scripting vulnerability in Fairsketch Rise Ultimate Project Manager 1.8 In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. | 5.4 |
2017-07-12 | CVE-2017-11180 | Cross-site Scripting vulnerability in Finecms Project Finecms FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen. | 6.1 |
2017-07-12 | CVE-2017-11179 | Cross-site Scripting vulnerability in Finecms Project Finecms FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account. | 6.1 |
2017-07-11 | CVE-2017-8569 | Cross-site Scripting vulnerability in Microsoft Sharepoint Server 2016 Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affected SharePoint server, aka "SharePoint Server XSS Vulnerability". | 8.8 |
2017-07-11 | CVE-2017-8560 | Cross-site Scripting vulnerability in Microsoft Exchange Server 2013/2016 Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". | 6.1 |
2017-07-11 | CVE-2017-8559 | Cross-site Scripting vulnerability in Microsoft Exchange Server 2013/2016 Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". | 6.1 |
2017-07-10 | CVE-2017-6734 | Cross-site Scripting vulnerability in Cisco Identity Services Engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected device, related to the Guest Portal. | 5.4 |
2017-07-10 | CVE-2017-6733 | Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.1(102.101)/2.2(0.283)/2.3(0.151) A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. | 6.1 |