Export limit exceeded: 46135 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46135 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2014-3827 | 1 Mybb | 1 Mybb | 2024-11-21 | 5.4 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser action or the name parameter in an (4) edit action in the user-user module or the (5) editprofile action to modcp.php. | ||||
| CVE-2014-3826 | 1 Mybb | 1 Mybb | 2024-11-21 | 5.4 Medium |
| Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module. | ||||
| CVE-2014-3809 | 1 Nokia | 6 1830 Photonic Service Switch-16, 1830 Photonic Service Switch-16 Firmware, 1830 Photonic Service Switch-32 and 3 more | 2024-11-21 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html. | ||||
| CVE-2014-3743 | 1 Marked Project | 1 Marked | 2024-11-21 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's. | ||||
| CVE-2014-3718 | 1 Exlibrisgroup | 1 Aleph 500 | 2024-11-21 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid parameter. | ||||
| CVE-2014-3656 | 1 Redhat | 1 Jboss Keycloak | 2024-11-21 | 6.1 Medium |
| JBoss KeyCloak: XSS in login-status-iframe.html | ||||
| CVE-2014-3650 | 1 Redhat | 1 Jboss Aerogear | 2024-11-21 | 5.4 Medium |
| Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input. | ||||
| CVE-2014-3649 | 1 Redhat | 1 Jboss Aerogear | 2024-11-21 | 6.1 Medium |
| JBoss AeroGear has reflected XSS via the password field | ||||
| CVE-2014-3592 | 1 Redhat | 1 Openshift Origin | 2024-11-21 | 6.1 Medium |
| OpenShift Origin: Improperly validated team names could allow stored XSS attacks | ||||
| CVE-2014-3413 | 1 Juniper | 1 Junos Space | 2024-11-21 | N/A |
| The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access. | ||||
| CVE-2014-3205 | 1 Seagate | 4 Blackarmor Nas 110, Blackarmor Nas 110 Firmware, Blackarmor Nas 220 and 1 more | 2024-11-21 | N/A |
| backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user. | ||||
| CVE-2014-2843 | 1 Infoware | 1 Mapsuite | 2024-11-21 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2014-2297 | 1 Videowhisper | 1 Videowhisper Live Streaming Integration | 2024-11-21 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4. | ||||
| CVE-2014-2214 | 1 Posh Project | 1 Posh | 2024-11-21 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) error parameter to /includes/plugins/mobile/scripts/login.php or (2) id parameter to portal/openrssarticle.php | ||||
| CVE-2014-1665 | 1 Owncloud | 1 Owncloud | 2024-11-21 | N/A |
| Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file. | ||||
| CVE-2014-1454 | 1 Pearson | 1 Esis Enterprise Student Information System | 2024-11-21 | 4.8 Medium |
| Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input | ||||
| CVE-2014-1427 | 1 Canonical | 1 Metal As A Service | 2024-11-21 | N/A |
| A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2. | ||||
| CVE-2014-1238 | 1 Ideagen | 1 Q-pulse | 2024-11-21 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier. | ||||
| CVE-2014-125109 | 1 Bestwebsoft | 1 Portfolio | 2024-11-21 | 3.5 Low |
| A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 2.28 is able to address this issue. The name of the patch is d2ede580474665af56ff262a05783fbabe4529b8. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248956. | ||||
| CVE-2014-125108 | 1 W3 | 1 Spell Checker | 2024-11-21 | 3.1 Low |
| A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The identifier of the patch is d6c21fd8187c5db2a50425ff80694149e75d722e. It is recommended to apply a patch to fix this issue. The identifier VDB-248849 was assigned to this vulnerability. | ||||