Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-25064 1 Show-me-the-way Project 1 Show-me-the-way 2024-11-21 4.0 MEDIUM 3.5 LOW
A vulnerability was found in OSM Lab show-me-the-way. It has been rated as problematic. This issue affects some unknown processing of the file js/site.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. The patch is named 4bed3b34dcc01fe6661f39c0e5d2285b340f7cac. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217439.
CVE-2018-25063 1 Zenoss 1 Dashboard 2024-11-21 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of the file ZenPacks/zenoss/Dashboard/browser/resources/js/defaultportlets.js. The manipulation of the argument HTMLString leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.3.5 is able to address this issue. The identifier of the patch is f462285a0a2d7e1a9255b0820240b94a43b00a44. It is recommended to upgrade the a ...

Show More

CVE-2018-25056 1 Yola 1 Yolapi 2024-11-21 N/A 3.5 LOW
A vulnerability, which was classified as problematic, was found in yolapi. Affected is the function render_description of the file yolapi/pypi/metadata.py. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a0fe129055a99f429133a5c40cb13b44611ff796. It is recommended to apply a patch to fix this issue. VDB-216966 is the identifier assigned to this vulnerability.
CVE-2018-25055 1 Farcry Solr Pro Project 1 Farcry Solr Pro 2024-11-21 N/A 3.5 LOW
A vulnerability was found in FarCry Solr Pro Plugin up to 1.5.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file packages/forms/solrProSearch.cfc of the component Search Handler. The manipulation of the argument suggestion leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.6.0 is able to address this issue. The name of the patch is b8f3d61511c9b02b781ec442bfb803cbff8e08d5. It is recommended to upg ...

Show More

CVE-2018-25054 1 Shredzone 1 Cilla 2024-11-21 N/A 3.5 LOW
A vulnerability was found in shred cilla. It has been classified as problematic. Affected is an unknown function of the file cilla-xample/src/main/webapp/WEB-INF/jsp/view/search.jsp of the component Search Handler. The manipulation of the argument details leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is d345e6bc7798bd717a583ec7f545ca387819d5c7. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-21 ...

Show More

CVE-2018-25053 1 Json2html 1 Json2html 2024-11-21 N/A 4.3 MEDIUM
A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file json2html.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.2.0 is able to address this issue. The name of the patch is 2d3d24d971b19a8ed1fb823596300b9835d55801. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216959.
CVE-2018-25052 1 Catalyst-plugin-session Project 1 Catalyst-plugin-session 2024-11-21 N/A 3.5 LOW
A vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and classified as problematic. This vulnerability affects the function _load_sessionid of the file lib/Catalyst/Plugin/Session.pm of the component Session ID Handler. The manipulation of the argument sid leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.41 is able to address this issue. The name of the patch is 88d1b599e1163761c9bd53bec53ba078f13e09d4. It is recommended to upgrade the a ...

Show More

CVE-2018-25051 1 Pomash Project 1 Pomash 2024-11-21 N/A 2.4 LOW
A vulnerability, which was classified as problematic, was found in JmPotato Pomash. This affects an unknown part of the file Pomash/theme/clean/templates/editor.html. The manipulation of the argument article.title/content.title/article.tag leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is be1914ef0a6808e00f51618b2de92496a3604415. It is recommended to apply a patch to fix this issue. The identifier VDB-216957 was assigned to this vulnerability ...

Show More

CVE-2018-25050 1 Getharvest 1 Chosen 2024-11-21 N/A 3.5 LOW
A vulnerability, which was classified as problematic, has been found in Harvest Chosen up to 1.8.6. Affected by this issue is the function AbstractChosen of the file coffee/lib/abstract-chosen.coffee. The manipulation of the argument group_label leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.7 is able to address this issue. The name of the patch is 77fd031d541e77510268d1041ed37798fdd1017e. It is recommended to upgrade the affected component. The iden ...

Show More

CVE-2018-25045 1 Django-rest-framework 1 Django Rest Framework 2024-11-21 N/A 6.1 MEDIUM
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
CVE-2018-25039 1 Technicolor 2 Thomson Tcw710, Thomson Tcw710 Firmware 2024-11-21 3.5 LOW 3.5 LOW
A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/RgUrlBlock.asp. The manipulation of the argument BasicParentalNewKeyword with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2018-25038 1 Technicolor 2 Thomson Tcw710, Thomson Tcw710 Firmware 2024-11-21 3.5 LOW 3.5 LOW
A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown part of the file /goform/RgDhcp. The manipulation of the argument PppUserName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2018-25037 1 Technicolor 2 Thomson Tcw710, Thomson Tcw710 Firmware 2024-11-21 3.5 LOW 3.5 LOW
A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/RgDdns. The manipulation of the argument DdnsHostName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2018-25036 1 Technicolor 2 Thomson Tcw710, Thomson Tcw710 Firmware 2024-11-21 3.5 LOW 3.5 LOW
A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/RgTime. The manipulation of the argument TimeServer1/TimeServer2/TimeServer3 with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2018-25035 1 Technicolor 2 Thomson Tcw710, Thomson Tcw710 Firmware 2024-11-21 3.5 LOW 3.5 LOW
A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown function of the file /goform/RGFirewallEL. The manipulation of the argument EmailAddress/SmtpServerName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2018-25034 1 Technicolor 2 Thomson Tcw710, Thomson Tcw710 Firmware 2024-11-21 3.5 LOW 3.5 LOW
A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05. This issue affects some unknown processing of the file /goform/wlanPrimaryNetwork. The manipulation of the argument ServiceSetIdentifier with the input ><script>alert(1)</script> as part of POST Request leads to basic cross site scripting (Persistent). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability ...

Show More

CVE-2018-21209 1 Netgear 20 Jnr1010, Jnr1010 Firmware, Jr6150 and 17 more 2024-11-21 3.5 LOW 4.8 MEDIUM
Certain NETGEAR devices are affected by reflected XSS. This affects JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.20, R6050 before 1.0.1.10, R6220 before 1.1.0.60, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.46, WNR2020 before 1.1.0.46, and WNR2050 before 1.1.0.46.
CVE-2018-21167 1 Netgear 42 D6100, D6100 Firmware, Dm200 and 39 more 2024-11-21 3.5 LOW 5.5 MEDIUM
Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.57, DM200 before 1.0.0.50, EX2700 before 1.0.1.32, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.70, EX6200v2 before 1.0.1.62, EX6400 before 1.0.1.78, EX7300 before 1.0.1.78, EX8000 before 1.0.0.114, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WN2000RPTv3 before 1.0.1.26, WN3000RPv3 before 1.0.2.66, WN3100RPv2 before 1.0.0.42, WNDR3700v4 be ...

Show More

CVE-2018-21155 1 Netgear 20 D7800, D7800 Firmware, Dm200 and 17 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.52, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, R7800 before 1.0.2.42, R8900 before 1.0.4.2, R9000 before 1.0.3.16, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64.
CVE-2018-21095 1 Netgear 4 Srr60, Srr60 Firmware, Srs60 and 1 more 2024-11-21 2.3 LOW 4.3 MEDIUM
Certain NETGEAR devices are affected by stored XSS. This affects SRR60 before 2.2.1.210 and SRS60 before 2.2.1.210.
CVE-2018-21030 1 Jupyter 1 Notebook 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
CVE-2018-21014 1 Buddyboss 1 Buddymoss Media 2024-11-21 3.5 LOW 5.4 MEDIUM
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
CVE-2018-21012 1 Vsourz 1 Cf7 Invisible Recaptcha 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
CVE-2018-21001 1 Bologer 1 Anycomment 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The anycomment plugin before 0.0.33 for WordPress has XSS.
CVE-2018-20986 1 Advancedcustomfields 1 Advanced Custom Fields 2024-11-21 3.5 LOW 5.4 MEDIUM
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
CVE-2018-20983 1 Meowapps 1 Wp Retina 2x 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
CVE-2018-20982 1 Davidlingren 1 Media Library Assistant 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
CVE-2018-20978 1 Soflyy 1 Wp All Import 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
CVE-2018-20975 1 Fatfreecrm 1 Fat Free Crm 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.
CVE-2018-20970 1 Bestwebsoft 1 Pdf \& Print 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
CVE-2018-20966 1 Booster 1 Booster For Woocommerce 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-20965 1 Ultimatemember 1 Ultimate Member 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
CVE-2018-20963 1 Codepeople 1 Contact Form Email 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2018-20962 1 Backpackforlaravel 1 Backpack\\crud 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
CVE-2018-20953 1 Cpanel 1 Cpanel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
CVE-2018-20951 1 Cpanel 1 Cpanel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
CVE-2018-20950 1 Cpanel 1 Cpanel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
CVE-2018-20949 1 Cpanel 1 Cpanel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
CVE-2018-20948 1 Cpanel 1 Cpanel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
CVE-2018-20935 1 Cpanel 1 Cpanel 2024-11-21 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).