Search Results (43212 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-16192 1 Limesurvey 1 Limesurvey 2024-11-21 6.1 Medium
LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
CVE-2020-16170 1 Robotemi 1 Temi 2024-11-21 7.5 High
Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.
CVE-2020-16157 1 Nagios 1 Log Server 2024-11-21 5.4 Medium
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
CVE-2020-16145 2 Fedoraproject, Roundcube 2 Fedora, Webmail 2024-11-21 6.1 Medium
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
CVE-2020-16140 1 Thembay 1 Greenmart 2024-11-21 6.1 Medium
The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.
CVE-2020-16131 1 Tiki 1 Tiki 2024-11-21 6.1 Medium
Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
CVE-2020-16095 1 Kitodo 1 Kitodo.presentation 2024-11-21 6.1 Medium
The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.
CVE-2020-16046 2 Apple, Google 2 Iphone Os, Chrome 2024-11-21 6.1 Medium
Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVE-2020-16030 1 Google 1 Chrome 2024-11-21 6.1 Medium
Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVE-2020-15952 1 Immuta 1 Immuta 2024-11-21 9.0 Critical
Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.
CVE-2020-15951 1 Immuta 1 Immuta 2024-11-21 6.1 Medium
Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.
CVE-2020-15948 1 Egain 1 Chat 2024-11-21 6.1 Medium
eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
CVE-2020-15944 1 Gantt-chart Project 1 Gantt-chart 2024-11-21 5.4 Medium
An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.
CVE-2020-15943 1 Gantt-chart Project 1 Gantt-chart 2024-11-21 8.1 High
An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.
CVE-2020-15940 1 Fortinet 1 Forticlient Enterprise Management Server 2024-11-21 4.1 Medium
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.
CVE-2020-15937 1 Fortinet 1 Fortios 2024-11-21 4.7 Medium
An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard.
CVE-2020-15930 1 Joplin Project 1 Joplin 2024-11-21 6.1 Medium
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
CVE-2020-15926 1 Rocket.chat 1 Rocket.chat 2024-11-21 6.1 Medium
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
CVE-2020-15919 1 Midasolutions 1 Eframework 2024-11-21 6.1 Medium
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
CVE-2020-15918 1 Midasolutions 1 Eframework 2024-11-21 5.4 Medium
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.