Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2016-9148 Cross-site Scripting vulnerability in CA Service Desk Manager 12.9/14.1
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.
network
low complexity
ca CWE-79
6.1
2017-03-06 CVE-2017-5197 Cross-site Scripting vulnerability in Silverstripe
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2.
network
low complexity
silverstripe CWE-79
6.1
2017-03-06 CVE-2017-6503 Cross-site Scripting vulnerability in Qbittorrent
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
network
low complexity
qbittorrent CWE-79
6.1
2017-03-05 CVE-2017-6446 Cross-site Scripting vulnerability in Dotclear 2.11.2
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
network
low complexity
dotclear CWE-79
6.1
2017-03-05 CVE-2017-6491 Cross-site Scripting vulnerability in Epesi 1.8.1.1
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1.
network
low complexity
epesi CWE-79
6.1
2017-03-05 CVE-2017-6490 Cross-site Scripting vulnerability in Epesi 1.8.1.1
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1.
network
low complexity
epesi CWE-79
6.1
2017-03-05 CVE-2017-6489 Cross-site Scripting vulnerability in Epesi 1.8.1.1
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1.
network
low complexity
epesi CWE-79
6.1
2017-03-05 CVE-2017-6488 Cross-site Scripting vulnerability in Epesi 1.8.1.1
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1.
network
low complexity
epesi CWE-79
6.1
2017-03-05 CVE-2017-6487 Cross-site Scripting vulnerability in Epesi 1.8.1.1
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1.
network
low complexity
epesi CWE-79
6.1
2017-03-05 CVE-2017-6486 Cross-site Scripting vulnerability in Reasoncms
A Cross-Site Scripting (XSS) issue was discovered in reasoncms before 4.7.1.
network
low complexity
reasoncms CWE-79
6.1