Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-06-09 CVE-2016-4906 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.
network
low complexity
cybozu CWE-79
6.1
2017-06-09 CVE-2016-7469 Cross-site Scripting vulnerability in F5 products
A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML.
network
low complexity
f5 CWE-79
5.4
2017-06-09 CVE-2017-9523 Cross-site Scripting vulnerability in Sophos web Appliance
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
network
low complexity
sophos CWE-79
6.1
2017-06-08 CVE-2017-1140 Cross-site Scripting vulnerability in IBM Business Process Manager
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-06-08 CVE-2015-1588 Cross-site Scripting vulnerability in Open-Xchange Appsuite and Open-Xchange Server
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.
network
low complexity
open-xchange CWE-79
6.1
2017-06-08 CVE-2017-9516 Cross-site Scripting vulnerability in Craftcms Craft CMS
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
network
low complexity
craftcms CWE-79
5.4
2017-06-07 CVE-2014-9310 Cross-site Scripting vulnerability in Wordpress Backup to Dropbox Project Wordpress Backup to Dropbox
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.
6.1
2017-06-07 CVE-2015-6959 Cross-site Scripting vulnerability in Vindula 1.9
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
network
low complexity
vindula CWE-79
5.4
2017-06-07 CVE-2015-6540 Cross-site Scripting vulnerability in Igcb Intellect Digital Core
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
network
low complexity
igcb CWE-79
6.1
2017-06-07 CVE-2017-1305 Cross-site Scripting vulnerability in IBM Rational Doors Next Generation 6.0.2/6.0.3
IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4