Export limit exceeded: 48153 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48153 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-9419 | 1 Webhammer | 1 Wp Custom Fields Search | 2025-04-20 | N/A |
| Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter. | ||||
| CVE-2017-9394 | 1 Ca | 1 Identity Governance | 2025-04-20 | N/A |
| A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user. | ||||
| CVE-2017-9366 | 1 Epesi | 1 Epesi | 2025-04-20 | N/A |
| Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter. | ||||
| CVE-2017-9356 | 1 Sitecore | 1 Sitecore.net | 2025-04-20 | N/A |
| Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. | ||||
| CVE-2017-9338 | 1 Owncloud | 1 Owncloud | 2025-04-20 | 5.4 Medium |
| Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue. | ||||
| CVE-2017-9337 | 1 Markdown On Save Improved Project | 1 Markdown On Save Improved | 2025-04-20 | N/A |
| The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post. | ||||
| CVE-2017-9336 | 1 Wp Editor.md Project | 1 Wp Editor.md | 2025-04-20 | N/A |
| The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post. | ||||
| CVE-2017-9332 | 1 Pivotx | 1 Pivotx | 2025-04-20 | N/A |
| The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag. | ||||
| CVE-2017-9331 | 1 Epesi | 1 Epesi | 2025-04-20 | N/A |
| The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted meeting description parameter. | ||||
| CVE-2017-9313 | 1 Webmin | 1 Webmin | 2025-04-20 | N/A |
| Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840. | ||||
| CVE-2017-9306 | 1 Syspass | 1 Syspass | 2025-04-20 | N/A |
| inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring. | ||||
| CVE-2017-9305 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2025-04-20 | N/A |
| lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php. | ||||
| CVE-2017-9299 | 1 Otrs | 1 Otrs | 2025-04-20 | N/A |
| Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20 release, for example, is not affected. | ||||
| CVE-2017-9298 | 1 Hitachi | 1 Device Manager | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to execute arbitrary JavaScript code. | ||||
| CVE-2017-9292 | 1 Lansweeper | 1 Lansweeper | 2025-04-20 | N/A |
| Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782. | ||||
| CVE-2017-9289 | 1 Note Project | 1 Note | 2025-04-20 | N/A |
| Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter). | ||||
| CVE-2017-9288 | 1 Raygun | 1 Raygun4wp | 2025-04-20 | N/A |
| The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter). | ||||
| CVE-2017-9252 | 1 Finecms Project | 1 Finecms | 2025-04-20 | N/A |
| andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action. | ||||
| CVE-2017-9251 | 1 Finecms Project | 1 Finecms | 2025-04-20 | N/A |
| andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php. | ||||
| CVE-2017-9249 | 1 Allen Disk Project | 1 Allen Disk | 2025-04-20 | 5.4 Medium |
| Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web script or HTML persistently by uploading a crafted HTML file. The attack vector is the content of this file, and the filename must be specified in the PATH_INFO to readfile.php. | ||||