Export limit exceeded: 381666 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 48416 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48416 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2016-1000137 | 1 Hero-maps-pro Project | 1 Hero-maps-pro | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin hero-maps-pro v2.1.0 | ||||
| CVE-2015-3935 | 1 Dolibarr | 1 Dolibarr | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (search_nom) field to (1) htdocs/societe/societe.php or (2) htdocs/societe/admin/societe.php. | ||||
| CVE-2015-3942 | 1 Garrettcom | 2 Magnum 10k Firmware, Magnum 6k Firmware | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in the web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2015-3948 | 1 Advantech | 1 Webaccess | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2015-3970 | 1 Janitza | 5 Umg 508, Umg 509, Umg 511 and 2 more | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2015-3988 | 3 Openstack, Oracle, Redhat | 3 Horizon, Solaris, Openstack | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate. | ||||
| CVE-2015-3989 | 1 Concrete5 | 1 Concrete5 | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors. | ||||
| CVE-2015-4029 | 1 Netgate | 1 Pfsense | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the zone parameter in a del action to services_captiveportal_zones.php. | ||||
| CVE-2016-1000136 | 1 Heat-trackr Project | 1 Heat-trackr | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin heat-trackr v1.0 | ||||
| CVE-2016-1000135 | 1 Hdw-tube Project | 1 Hdw-tube | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin hdw-tube v1.2 | ||||
| CVE-2016-1000133 | 1 Designsandcode | 1 Forget About Shortcode Buttons | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1 | ||||
| CVE-2015-4413 | 1 Nextendweb | 1 Facebook Connect | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. | ||||
| CVE-2016-1000132 | 1 Cminds | 1 Tooltip Glossary | 2025-04-12 | N/A |
| Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8 | ||||
| CVE-2015-4420 | 1 Opsview | 1 Opsview | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Test service check page. | ||||
| CVE-2015-4427 | 1 Ektron | 1 Ektron Content Management System | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users to inject arbitrary web script or HTML via the (1) page, (2) action, (3) folder_id, or (4) LangType parameter. | ||||
| CVE-2015-4465 | 1 Zanematthew | 1 Zm Ajax Login \& Register | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2015-4490 | 4 Canonical, Mozilla, Opensuse and 1 more | 4 Ubuntu Linux, Firefox, Opensuse and 1 more | 2025-04-12 | N/A |
| The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior. | ||||
| CVE-2015-4518 | 1 Mozilla | 1 Firefox | 2025-04-12 | N/A |
| The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL. | ||||
| CVE-2016-1918 | 1 Blackberry | 1 Enterprise Server | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1917. | ||||
| CVE-2015-4528 | 1 Emc | 1 Documentum Centerstage | 2025-04-12 | N/A |
| Cross-site scripting (XSS) vulnerability in EMC Documentum CenterStage 1.2SP1 and 1.2SP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||||