Export limit exceeded: 48153 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48153 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-7388 | 1 Wallaceit | 1 Wallacepos | 2025-04-20 | 6.1 Medium |
| A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos-master/myaccount/resetpassword.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | ||||
| CVE-2017-7387 | 1 Helpmewatchwho Project | 1 Helpmewatchwho | 2025-04-20 | N/A |
| TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter). | ||||
| CVE-2017-7386 | 1 Symetrie Project | 1 Symetrie | 2025-04-20 | N/A |
| citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter). | ||||
| CVE-2017-7384 | 1 Flipbuilder | 1 Flip Pdf | 2025-04-20 | N/A |
| Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF allows remote attackers to inject arbitrary web script or HTML via the currentHTMLURL parameter. | ||||
| CVE-2017-7363 | 1 Lucidcrew | 1 Pixie | 2025-04-20 | N/A |
| Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | ||||
| CVE-2017-7362 | 1 Lucidcrew | 1 Pixie | 2025-04-20 | N/A |
| Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | ||||
| CVE-2017-7361 | 1 Lucidcrew | 1 Pixie | 2025-04-20 | N/A |
| Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | ||||
| CVE-2017-7360 | 1 Lucidcrew | 1 Pixie | 2025-04-20 | N/A |
| Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | ||||
| CVE-2017-7359 | 1 Lucidcrew | 1 Pixie | 2025-04-20 | N/A |
| Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | ||||
| CVE-2017-7352 | 1 Purestorage | 1 Purity | 2025-04-20 | 5.4 Medium |
| Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject arbitrary web script or HTML via the "host" parameter on the 'System > Configuration > SNMP > Add SNMP Trap Manager' screen. | ||||
| CVE-2017-7339 | 1 Fortinet | 1 Fortiportal | 2025-04-20 | N/A |
| A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality. | ||||
| CVE-2017-7336 | 1 Fortinet | 1 Fortiwlm | 2025-04-20 | N/A |
| A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges. | ||||
| CVE-2017-7335 | 1 Fortinet | 1 Fortiwlc | 2025-04-20 | N/A |
| A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject arbitrary web script or HTML via non-sanitized parameters "refresh" and "branchtotable" present in HTTP POST requests. | ||||
| CVE-2017-7320 | 1 Modx | 1 Modx Revolution | 2025-04-20 | 6.1 Medium |
| setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value. | ||||
| CVE-2017-7309 | 1 Mantisbt | 1 Mantisbt | 2025-04-20 | N/A |
| A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3. | ||||
| CVE-2017-7298 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. | ||||
| CVE-2017-7296 | 1 Contiki-os | 1 Contiki | 2025-04-20 | N/A |
| An issue was discovered in Contiki Operating System 3.0. A Persistent XSS vulnerability is present in the MQTT/IBM Cloud Config page (aka mqtt.html) of cc26xx-web-demo. The cc26xx-web-demo features a webserver that runs on a constrained device. That particular page allows a user to remotely configure that device's operation by sending HTTP POST requests. The vulnerability consists of improper input sanitisation of the text fields on the MQTT/IBM Cloud config page, allowing for JavaScript code injection. | ||||
| CVE-2017-7288 | 1 Synacor | 1 Zimbra Collaboration Suite | 2025-04-20 | N/A |
| Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-7276 | 1 Topdesk | 1 Topdesk | 2025-04-20 | N/A |
| There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019. | ||||
| CVE-2017-7271 | 1 Yii Software | 1 Yii | 2025-04-20 | N/A |
| Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen. | ||||