Export limit exceeded: 372403 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (47806 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-9760 1 Gosa Project 1 Gosa 2025-04-20 6.1 Medium
Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username.
CVE-2014-9905 1 Alinto 1 Sogo 2025-04-20 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) contact fields.
CVE-2014-9916 1 Bilboplanet 1 Bilboplanet 2025-04-20 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
CVE-2015-1864 1 Kallithea-scm 1 Kallithea 2025-04-20 N/A
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.
CVE-2015-1866 1 Emberjs 1 Ember.js 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
CVE-2015-3257 1 Zend 1 Diactoros 2025-04-20 N/A
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
CVE-2015-3296 1 Nodebb 1 Nodebb 2025-04-20 N/A
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.
CVE-2015-3299 1 Floating Social Bar Project 1 Floating Social Bar 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order.
CVE-2015-3421 1 Eshop Project 1 Eshop 2025-04-20 N/A
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
CVE-2015-5057 1 Broken Link Checker Project 1 Broken Link Checker 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.
CVE-2015-5060 1 Anchorcms 1 Anchor Cms 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
CVE-2015-5181 1 Redhat 3 Jboss A-mq, Jboss Amq, Jboss Fuse 2025-04-20 N/A
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
CVE-2015-5282 2 Redhat, Theforeman 3 Satellite, Satellite Capsule, Foreman 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
CVE-2015-6027 1 Castlerock 1 Snmpc 2025-04-20 6.1 Medium
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
CVE-2015-6021 1 Spiceworks 1 Desktop 2025-04-20 N/A
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
CVE-2015-6035 1 Opsview 1 Opsview 2025-04-20 N/A
Opsview before 2015-11-06 has XSS via SNMP.
CVE-2015-6942 1 Coremail 1 Coremail Xt 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment.
CVE-2015-6959 1 Vindula 1 Vindula 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
CVE-2015-7672 1 Centreon 1 Centreon 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
CVE-2015-7711 1 Atutor 1 Atutor 2025-04-20 N/A
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.