Total
37603 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-17865 | 1 Sap | 1 J2ee Engine | 2024-11-21 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
CVE-2018-17862 | 1 Sap | 1 J2ee Engine | 2024-11-21 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
CVE-2018-17861 | 1 Sap | 1 J2ee Engine | 2024-11-21 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
CVE-2018-17849 | 1 Naviwebs | 1 Navigate Cms | 2024-11-21 | N/A |
Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload. | ||||
CVE-2018-17835 | 1 Get-simple | 1 Getsimple Cms | 2024-11-21 | N/A |
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI. | ||||
CVE-2018-17832 | 1 Wuzhicms | 1 Wuzhi Cms | 2024-11-21 | N/A |
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | ||||
CVE-2018-17830 | 1 Redaxo | 1 Redaxo | 2024-11-21 | N/A |
The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring. | ||||
CVE-2018-17790 | 1 Prospecta | 1 Master Data Online | 2024-11-21 | 5.4 Medium |
Prospecta Master Data Online (MDO) 2.0 has Stored XSS. | ||||
CVE-2018-17784 | 1 Sugarcrm | 1 Sugarcrm | 2024-11-21 | 6.1 Medium |
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. | ||||
CVE-2018-17783 | 1 Mantisbt | 1 Mantisbt | 2024-11-21 | N/A |
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name. | ||||
CVE-2018-17782 | 1 Mantisbt | 1 Mantisbt | 2024-11-21 | N/A |
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name. | ||||
CVE-2018-17596 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2024-11-21 | N/A |
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. | ||||
CVE-2018-17595 | 1 Fork-cms | 1 Fork Cms | 2024-11-21 | N/A |
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI. | ||||
CVE-2018-17594 | 1 Airties | 2 Air 5443v2, Air 5443v2 Firmware | 2024-11-21 | N/A |
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||||
CVE-2018-17593 | 1 Airties | 2 Air 5453, Air 5453 Firmware | 2024-11-21 | N/A |
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||||
CVE-2018-17591 | 1 Airties | 2 Air 5343v2, Air 5343v2 Firmware | 2024-11-21 | N/A |
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||||
CVE-2018-17590 | 1 Airties | 2 Air 5442, Air 5442 Firmware | 2024-11-21 | N/A |
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||||
CVE-2018-17589 | 1 Airties | 2 Air 5650, Air 5650 Firmware | 2024-11-21 | N/A |
AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||||
CVE-2018-17588 | 1 Airties | 2 Air 5021, Air 5021 Firmware | 2024-11-21 | N/A |
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. | ||||
CVE-2018-17587 | 1 Airties | 2 Air 5750, Air 5750 Firmware | 2024-11-21 | N/A |
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |