Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-33295 | 1 Joplin Project | 1 Joplin | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
|
|||||
| CVE-2021-33212 | 1 Element-it | 1 Http Commander | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SVG image.
|
|||||
| CVE-2021-33192 | 1 Apache | 1 Jena Fuseki | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive).
|
|||||
| CVE-2021-33179 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
|
|||||
| CVE-2021-33041 | 1 Vmd Project | 1 Vmd | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
|
|||||
| CVE-2021-33040 | 1 Futurepress | 1 Epub.js | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.
|
|||||
| CVE-2021-33025 | 1 Xarrow | 1 Xarrow | 2024-11-21 | 4.6 MEDIUM | 5.6 MEDIUM |
|
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
|
|||||
| CVE-2021-33021 | 1 Xarrow | 1 Xarrow | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
|
|||||
| CVE-2021-33001 | 1 Xarrow | 1 Xarrow | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.
|
|||||
| CVE-2021-32989 | 1 Lcds | 1 Laquis Scada | 2024-11-21 | 4.3 MEDIUM | 9.3 CRITICAL |
|
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
|
|||||
| CVE-2021-32962 | 1 Aggsoft | 1 Webserver | 2024-11-21 | 4.3 MEDIUM | 8.2 HIGH |
|
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.
|
|||||
| CVE-2021-32927 | 1 Uffizio | 1 Gps Tracker | 2024-11-21 | 4.3 MEDIUM | 7.1 HIGH |
|
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.
|
|||||
| CVE-2021-32862 | 2 Debian, Jupyter | 2 Debian Linux, Nbconvert | 2024-11-21 | N/A | 7.5 HIGH |
|
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
|
|||||
| CVE-2021-32860 | 1 Izimodal Project | 1 Izimodal | 2024-11-21 | N/A | 6.1 MEDIUM |
|
iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field `title` when creating a `iziModal` instance is able to supply arbitrary `html` or `javascript` code that will be rendered in the context of a user, potentially leading to `XSS`. Version 1.6.1 contains a patch for this issue
|
|||||
| CVE-2021-32859 | 1 Baremetrics | 1 Date Range Picker | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the field `placeholder` when creating a `Calendar` instance is able to supply arbitrary `html` or `javascript` that will be rendered in the context of a user leading to XSS. There are no known patches for this issue.
|
|||||
| CVE-2021-32858 | 1 Esdoc | 1 Esdoc-publish-html-plugin | 2024-11-21 | N/A | 6.1 MEDIUM |
|
esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-html-plugin 1.1.2 and prior can be bypassed which may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
|
|||||
| CVE-2021-32857 | 1 Agentejo | 1 Cockpit | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
|
|||||
| CVE-2021-32856 | 1 Microweber | 1 Microweber | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete.
|
|||||
| CVE-2021-32855 | 1 B3log | 1 Vditor | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. Version 3.8.7 contains a patch for this issue.
|
|||||
| CVE-2021-32854 | 1 Textangular | 1 Textangular | 2024-11-21 | N/A | 6.1 MEDIUM |
|
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
|
|||||
| CVE-2021-32853 | 1 Erxes | 1 Erxes | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.
|
|||||
| CVE-2021-32852 | 1 Count | 1 Countly Server | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirected there from malicious web site. The attacker must have an account or be able to create one. This issue is patched in version 21.11.
|
|||||
| CVE-2021-32851 | 1 Mind-elixir Project | 1 Mind-elixir | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue is patched in version 0.18.1
|
|||||
| CVE-2021-32850 | 1 Jquery-minicolors Project | 1 Jquery-minicolors | 2024-11-21 | N/A | 6.1 MEDIUM |
|
jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6.
|
|||||
| CVE-2021-32828 | 1 Hyland | 1 Nuxeo | 2024-11-21 | N/A | 5.4 MEDIUM |
|
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
|
|||||
| CVE-2021-32827 | 2 Mock-server, Oracle | 2 Mockserver, Communications Cloud Native Core Policy | 2024-11-21 | 6.8 MEDIUM | 6.1 MEDIUM |
|
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine. With an overly broad default CORS configuration MockServer allows any site to send cross-site requests. Additionally, MockServer allows you to create dynamic expectations using Javascript or Velocity templates. Both engines ...
Show More |
|||||
| CVE-2021-32818 | 1 Haml-coffee Project | 1 Haml-coffee | 2024-11-21 | 3.5 LOW | 7.7 HIGH |
|
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its configuration options. A vulnerable application that passes user controlled request objects to the haml-coffee template engine may introduce RCE vulnerabilities. Additionally control over the escapeHtml parameter through template configuration polluti ...
Show More |
|||||
| CVE-2021-32812 | 1 Tekmonks | 1 Monkshu | 2024-11-21 | 4.3 MEDIUM | 4.6 MEDIUM |
|
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in frontend HTTP server. The attacker can send in a carefully crafted URL along with a known bug in the server which will cause a 500 error, and the response will then embed the URL provided by the hacker. The impact is moderate as the hacker must also be able to craft an HTTP request whi ...
Show More |
|||||
| CVE-2021-32809 | 3 Ckeditor, Fedoraproject, Oracle | 10 Ckeditor, Fedora, Application Express and 7 more | 2024-11-21 | 3.5 LOW | 4.6 MEDIUM |
|
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in ver ...
Show More |
|||||
| CVE-2021-32808 | 3 Ckeditor, Fedoraproject, Oracle | 13 Ckeditor, Fedora, Application Express and 10 more | 2024-11-21 | 3.5 LOW | 7.6 HIGH |
|
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.
|
|||||
| CVE-2021-32798 | 1 Jupyter | 1 Notebook | 2024-11-21 | 6.8 MEDIUM | 10.0 CRITICAL |
|
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.
|
|||||
| CVE-2021-32797 | 1 Jupyter | 1 Jupyterlab | 2024-11-21 | 6.8 MEDIUM | 7.4 HIGH |
|
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.
|
|||||
| CVE-2021-32793 | 1 Pi-hole | 1 Pi-hole | 2024-11-21 | 3.5 LOW | 5.7 MEDIUM |
|
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-scripting vulnerability. User input added as a wildcard domain to a blocklist or allowlist is unfiltered in the web interface. Since the payload is stored permanently as a wildcard domain, this is a persistent XSS vulnerability. A remote attacke ...
Show More |
|||||
| CVE-2021-32792 | 3 Apache, Fedoraproject, Openidc | 3 Http Server, Fedora, Mod Auth Openidc | 2024-11-21 | 4.3 MEDIUM | 3.1 LOW |
|
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.
|
|||||
| CVE-2021-32782 | 1 Nextcloud | 1 Circles | 2024-11-21 | 3.5 LOW | 5.8 MEDIUM |
|
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. It is recommended that the Nextcloud Circles application is upgraded to 0.21.3, 0.20.10 or 0.19.14 to resolve this issue. As a workaround users ...
Show More |
|||||
| CVE-2021-32772 | 1 Electronjs | 1 Poddycast | 2024-11-21 | 4.3 MEDIUM | 8.8 HIGH |
|
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of HTML and JS code (cross-site scripting). Being an application made in electron, cross-site scripting can be scaled to remote code execution, making it possible to execute commands on ...
Show More |
|||||
| CVE-2021-32768 | 1 Typo3 | 1 Typo3 | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site scripting. Corresponding rendering instructions via TypoScript functionality HTMLparser does not consider all potentially malicious HTML tag & attribute combinations per default. In default scenarios, a valid backend user account ...
Show More |
|||||
| CVE-2021-32764 | 1 Discourse | 1 Discourse | 2024-11-21 | 3.5 LOW | 8.1 HIGH |
|
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. The issue is patched in `stable` version 2.7.6, `beta` version 2.8.0.beta3, and `tests-passed` version 2.8.0.beta3. As a workaround, ensure that the Content Security Policy is enabled, and has not been modified in a way ...
Show More |
|||||
| CVE-2021-32750 | 1 Muwire Project | 1 Muwire | 2024-11-21 | 3.5 LOW | 6.8 MEDIUM |
|
MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users of MuWire desktop client prior to version 0.8.8 can be de-anonymized by an attacker who knows their full ID. An attacker could send a message with a subject line containing a URL with an HTML image tag and the MuWire client would try to fetch that image via clearnet, thus exposing the IP address of the user. The problem is fixed in MuWire 0.8.8. As a workaround, users can disabl ...
Show More |
|||||
| CVE-2021-32745 | 1 Collabora | 1 Online | 2024-11-21 | 4.3 MEDIUM | 7.3 HIGH |
|
Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. The issue i ...
Show More |
|||||