Search Results (49026 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-9714 1 Facebook 1 Hiphop Virtual Machine 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function.
CVE-2010-5314 1 Chialab \& Channelweb 1 Bedita 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in controllers/home_controller.php in BEdita before 3.1 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter to news/index.
CVE-2014-3365 1 Cisco 1 Prime Security Manager 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.
CVE-2015-8247 1 Synnefoims 1 Internet Management Software 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.
CVE-2015-1564 1 Plainblack 1 Webgui 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field.
CVE-2015-3626 1 Fortinet 1 Fortios 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the DHCP Monitor page in the Web User Interface (WebUI) in Fortinet FortiOS before 5.2.4 on FortiGate devices allows remote attackers to inject arbitrary web script or HTML via a crafted hostname.
CVE-2016-9998 1 Spip 1 Spip 2025-04-12 N/A
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.
CVE-2015-3362 1 Video Project 1 Video 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Video module before 7.x-2.11 for Drupal, when using the video WYSIWYG plugin, allows remote authenticated users to inject arbitrary web script or HTML via a node title.
CVE-2016-1000131 1 E-search Project 1 Esearch 2025-04-12 N/A
Reflected XSS in wordpress plugin e-search v1.0
CVE-2016-1000132 1 Cminds 1 Tooltip Glossary 2025-04-12 N/A
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
CVE-2016-1000136 1 Heat-trackr Project 1 Heat-trackr 2025-04-12 N/A
Reflected XSS in wordpress plugin heat-trackr v1.0
CVE-2015-5441 1 Hp 2 Archsight Management Center, Arcsight Logger 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-3359 1 Room Reservations Project 1 Room Reservations 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remote authenticated users with the "Administer the room reservations system" permission to inject arbitrary web script or HTML via the (1) node title of a "Room Reservations Category" or (2) body of a "Room Reservations Room" node.
CVE-2015-5454 1 Nucleuscms 1 Nucleus Cms 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.
CVE-2016-1000152 1 Tidio-form Project 1 Tidio-form 2025-04-12 N/A
Reflected XSS in wordpress plugin tidio-form v1.0
CVE-2015-5456 1 Pivotx 1 Pivotx 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the "PHP_SELF" variable and form actions.
CVE-2015-5460 1 Snorby Project 1 Snorby 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification.
CVE-2015-3353 1 Field Display Label Project 1 Field Display Label 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Field Display Label module before 7.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the alternate field label in content types settings.
CVE-2015-5475 1 Bestpractical 1 Request Tracker 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
CVE-2013-2087 1 Galleryproject 1 Gallery 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.