Export limit exceeded: 381404 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48382 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2016-1000147 | 1 Recipes-writer Project | 1 Recipes-writer | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin recipes-writer v1.0.4 | ||||
| CVE-2016-1000148 | 1 S3-video Project | 1 S3-video | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin s3-video v0.983 | ||||
| CVE-2016-1000150 | 1 Oxil | 1 Simplified-content | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin simplified-content v1.0.0 | ||||
| CVE-2016-1000151 | 1 Tera-charts Project | 1 Tera-charts | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin tera-charts v1.0 | ||||
| CVE-2016-1000153 | 1 Tidio-gallery Project | 1 Tidio-gallery | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin tidio-gallery v1.1 | ||||
| CVE-2016-1000154 | 1 Browserweb | 1 Whizz | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin whizz v1.0.7 | ||||
| CVE-2016-1000155 | 1 Wpsolr | 1 Wpsolr-search-engine | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin wpsolr-search-engine v7.6 | ||||
| CVE-2016-10006 | 1 Antisamy Project | 1 Antisamy | 2025-04-12 | 6.1 Medium |
| In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS. | ||||
| CVE-2016-1136 | 1 Kddi | 2 Home Spot Cube, Home Spot Cube Firmware | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1144 | 1 Websquare | 1 Job-cube | 2025-04-12 | 5.4 Medium |
| Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1149 | 1 Cybozu | 1 Office | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1150. | ||||
| CVE-2016-1150 | 1 Cybozu | 1 Office | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149. | ||||
| CVE-2016-1157 | 1 Log-chat Project | 1 Log-chat | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in log_chat.cgi in Script* Log-Chat before 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1207 | 1 Iodata | 6 Wn-g300r, Wn-g300r2, Wn-g300r2 Firmware and 3 more | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1211 | 1 Epoch | 1 Web Mailing List | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in Epoch Web Mailing List 0.31 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1230 | 1 Ntt | 1 Webarena Service Formmail | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1592 | 1 Netiq | 1 Identity Manager | 2025-04-12 | N/A |
| XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. | ||||
| CVE-2016-2081 | 1 Vmware | 1 Vrealize Log Insight | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2016-1911 | 1 Sap | 1 Netweaver | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) Runtime Workbench (RWB) or (2) Pmitest servlet in the Process Monitoring Infrastructure (PMI), aka SAP Security Notes 2206793 and 2234918. | ||||
| CVE-2016-1912 | 1 Dolibarr | 1 Dolibarr | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php. | ||||