Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2016-02-10 CVE-2015-7679 Cross-site Scripting vulnerability in Ipswitch Moveit Mobile 1.2.0.962
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
network
low complexity
ipswitch CWE-79
6.1
2016-02-10 CVE-2016-0039 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation 2013
Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
network
low complexity
microsoft CWE-79
6.1
2016-02-09 CVE-2016-1318 Cross-site Scripting vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module 1.1Base
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489.
network
low complexity
cisco CWE-79
6.1
2016-02-08 CVE-2016-2214 Cross-site Scripting vulnerability in Huawei Agile Controller-Campus V100R001C00Spc315
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
low complexity
huawei CWE-79
6.1
2016-02-07 CVE-2016-1309 Cross-site Scripting vulnerability in Cisco Webex Meetings Server 2.5.1.5
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01843.
network
low complexity
cisco CWE-79
6.1
2016-02-07 CVE-2016-1305 Cross-site Scripting vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module 1.1Base
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML entities, aka Bug ID CSCux15511.
network
low complexity
cisco CWE-79
6.1
2016-02-06 CVE-2016-1311 Cross-site Scripting vulnerability in Cisco Jabber Guest 10.6.8
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, aka Bug ID CSCuy08224.
network
low complexity
cisco CWE-79
6.1
2016-02-06 CVE-2016-1310 Cross-site Scripting vulnerability in SUN Opensolaris Snv124
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.
network
low complexity
sun CWE-79
6.1
2016-02-06 CVE-2016-1306 Cross-site Scripting vulnerability in SUN Opensolaris Snv124
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466.
network
low complexity
sun CWE-79
6.1
2016-02-06 CVE-2015-7916 Cross-site Scripting vulnerability in Sauter-Controls Moduweb Vision 1.5
Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.
network
low complexity
sauter-controls CWE-79
6.5