Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-13073 1 Qnap 1 Photo Station 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
CVE-2017-13072 1 Qnap 1 Qts 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
CVE-2017-12885 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
CVE-2017-12788 1 Metinfo 1 Metinfo 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.
CVE-2017-12614 1 Apache 1 Airflow 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
CVE-2017-12590 1 Asus 2 Rt-n14uhp, Rt-n14uhp Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.
CVE-2017-12544 3 Hp, Linux, Microsoft 3 System Management Homepage, Linux Kernel, Windows 2024-11-21 3.5 LOW 5.4 MEDIUM
A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
CVE-2017-12307 1 Cisco 170 Esw2-350g-52, Esw2-350g-52 Firmware, Esw2-350g-52dc and 167 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting and inj ...

Show More

CVE-2017-12175 1 Redhat 1 Satellite 2024-11-21 3.5 LOW 3.5 LOW
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
CVE-2017-12098 1 Rails Admin Project 1 Rails Admin 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.
CVE-2017-12097 1 Delayed Job Web Project 1 Delayed Job Web 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.
CVE-2017-11739 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.
CVE-2017-11650 1 Draytek 2 Vigorap 910c, Vigorap 910c Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp.
CVE-2017-11560 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.
CVE-2017-11175 1 Siemens 1 Fin Stack 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.
CVE-2017-1002201 2 Debian, Haml 2 Debian Linux, Haml 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
CVE-2017-1002152 1 Redhat 1 Bodhi 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
CVE-2017-1000510 1 Croogo 1 Croogo 2024-11-21 3.5 LOW 5.4 MEDIUM
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
CVE-2017-1000509 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 3.5 LOW 5.4 MEDIUM
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
CVE-2017-1000508 1 Invoiceplane 1 Invoiceplane 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.
CVE-2017-1000507 1 Cnvs 1 Canvas 2024-11-21 3.5 LOW 5.4 MEDIUM
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
CVE-2017-1000506 1 Mautic 1 Mautic 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
CVE-2017-1000495 1 Quickappscms 1 Quickapps Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
CVE-2017-1000492 1 Leanote 1 Desktop 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
CVE-2017-1000491 1 Shiba Project 1 Shiba 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
CVE-2017-1000488 2 Acquia, Mautic 2 Mautic, Mautic 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
CVE-2017-1000482 1 Plone 1 Plone 2024-11-21 3.5 LOW 5.4 MEDIUM
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
CVE-2017-1000478 1 Elabftw 1 Elabftw 2024-11-21 3.5 LOW 5.4 MEDIUM
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.
CVE-2017-1000467 1 Lavalite 1 Lavalite 2024-11-21 3.5 LOW 5.4 MEDIUM
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000466 1 Invoiceninja 1 Invoice Ninja 2024-11-21 3.5 LOW 5.4 MEDIUM
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000465 1 Sulu 1 Sulu-standard 2024-11-21 3.5 LOW 5.4 MEDIUM
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000463 1 Leafpub 1 Leafpub 2024-11-21 3.5 LOW 5.4 MEDIUM
Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000462 1 Bookstackapp 1 Bookstack 2024-11-21 3.5 LOW 5.4 MEDIUM
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000459 1 Leanote 1 Leanote 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
CVE-2017-1000457 1 Mojoportal 1 Mojoportal 2024-11-21 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.
CVE-2017-1000443 1 Openhacker Project 1 Openhacker 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.
CVE-2017-1000442 1 Passbolt 1 Passbolt Api 2024-11-21 3.5 LOW 5.4 MEDIUM
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
CVE-2017-1000431 1 Ez 1 Ez Publish 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
CVE-2017-1000429 1 Finecms Project 1 Finecms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.
CVE-2017-1000428 1 Flatcore 1 Flatcore-cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.