Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-03-29 CVE-2017-2687 Cross-site Scripting vulnerability in Siemens Ruggedcom ROX I 2.9.0
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.
network
low complexity
siemens CWE-79
6.1
2017-03-28 CVE-2016-9473 Cross-site Scripting vulnerability in Brave Browser 1.2.16/1.9.56
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.
network
low complexity
brave CWE-79
4.7
2017-03-28 CVE-2016-9472 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9466 Cross-site Scripting vulnerability in multiple products
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application.
network
low complexity
owncloud nextcloud CWE-79
6.1
2017-03-28 CVE-2016-9465 Cross-site Scripting vulnerability in multiple products
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export.
network
low complexity
owncloud nextcloud CWE-79
5.4
2017-03-28 CVE-2016-9459 Cross-site Scripting vulnerability in multiple products
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS.
network
low complexity
owncloud nextcloud CWE-79
6.1
2017-03-28 CVE-2016-9457 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9454 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9130 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from Persistent XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9128 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.3 suffers from reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4