CVEs from 2016
Total
8,525
critical
critical 1,164
high
high 3,521
medium
medium 3,172
low
low 249
% Critical
13.7%
% with KEV
0.7%
% with exploit
0.9%
Top vendors
Top products
- phpmyadmin 3,382
- php 1,748
- squid 1,549
- samba 1,093
- drupal 868
- firefox 757
- moodle 700
- openssl 664
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2016-0808 | medium | 6.2 | 6.2 | 10y ago | Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of serv… | |
| CVE-2016-0602 | medium | — | 6.2 | 11y ago | Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.14 allows local users to affect confidentiality, integrity, and availability via unknown… | |
| CVE-2016-7148 | medium | 6.1 | 6.1 | 4y ago | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile… | |
| CVE-2016-9119 | medium | 6.1 | 6.1 | 4y ago | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| CVE-2016-7137 | medium | 6.1 | 6.1 | 4y ago | Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing… | |
| CVE-2016-7136 | medium | 6.1 | 6.1 | 4y ago | z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request. | |
| CVE-2016-10704 | medium | 6.1 | 6.1 | 9y ago | Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503. | |
| CVE-2016-10702 | medium | 6.1 | 6.1 | 9y ago | Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by mo… | |
| CVE-2016-10699 | medium | 6.1 | 6.1 | 9y ago | D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a remote unauthenticated user may craft logins and passwords with script tags in the… | |
| CVE-2016-10516 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote… | |
| CVE-2016-10515 | medium | 6.1 | 6.1 | 9y ago | In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages. | |
| CVE-2016-4923 | medium | 6.1 | 6.1 | 9y ago | Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a remote unauthenticated user to inject web script or HTML and steal sensitive data … | |
| CVE-2016-10513 | medium | 6.1 | 6.1 | 9y ago | Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php. | |
| CVE-2016-10510 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection m… | |
| CVE-2016-10508 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in demo/phpThumb.demo.showpic.php. | |
| CVE-2016-6800 | medium | 6.1 | 6.1 | 9y ago | The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creatio… | |
| CVE-2016-6812 | medium | 6.1 | 6.1 | 9y ago | Improper Neutralization of Input During Web Page Generation in Apache CXF | |
| CVE-2016-3113 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML. | |
| CVE-2016-10404 | medium | 6.1 | 6.1 | 9y ago | Liferay Portal Vulnerable to XSS via a Crafted Redirect Field | |
| CVE-2016-6133 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus para… | |
| CVE-2016-5394 | medium | 6.1 | 6.1 | 9y ago | Cross site scripting in Apache Sling | |
| CVE-2016-8947 | medium | 6.1 | 6.1 | 9y ago | IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a re… | |
| CVE-2016-6201 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the ContTy… | |
| CVE-2016-6127 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allow… | |
| CVE-2016-10366 | medium | 6.1 | 6.1 | 9y ago | Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. | |
| CVE-2016-10365 | medium | 6.1 | 6.1 | 9y ago | Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website. | |
| CVE-2016-1000220 | medium | 6.1 | 6.1 | 9y ago | Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers. | |
| CVE-2016-7831 | medium | 6.1 | 6.1 | 9y ago | Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the URL display via a specially crafted webpage. | |
| CVE-2016-7817 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in Simple keitai chat 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| CVE-2016-7813 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in DERAEMON-CMS version 0.8.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the parameters hostname, database and username. | |
| CVE-2016-7808 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| CVE-2016-4906 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai. | |
| CVE-2016-9834 | medium | 6.1 | 6.1 | 9y ago | An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is … | |
| CVE-2016-0781 | medium | 6.1 | 6.1 | 9y ago | The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions p… | |
| CVE-2016-4903 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified v… | |
| CVE-2016-4859 | medium | 6.1 | 6.1 | 9y ago | Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk… | |
| CVE-2016-4857 | medium | 6.1 | 6.1 | 9y ago | Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.11 and Splunk Light prior to 6.4.2 allows to redire… | |
| CVE-2016-4855 | medium | 6.1 | 6.1 | 9y ago | ADOdb Cross-site scripting vulnerability in old test script | |
| CVE-2016-9099 | medium | 6.1 | 6.1 | 9y ago | Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability… | |
| CVE-2016-9257 | medium | 6.1 | 6.1 | 9y ago | In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when … | |
| CVE-2016-0255 | medium | 6.1 | 6.1 | 9y ago | IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject ma… | |
| CVE-2016-10368 | medium | 6.1 | 6.1 | 9y ago | Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers … | |
| CVE-2016-7841 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| CVE-2016-7840 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web script or HTML via the month parameter. | |
| CVE-2016-7839 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| CVE-2016-4075 | medium | 6.1 | 6.1 | 9y ago | Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL. | |
| CVE-2016-1217 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2. | |
| CVE-2016-1216 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. | |
| CVE-2016-1215 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. | |
| CVE-2016-1214 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. | |
| CVE-2016-1213 | medium | 6.1 | 6.1 | 9y ago | The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. | |
| CVE-2016-6347 | medium | 6.1 | 6.1 | 9y ago | Improper Neutralization of Input During Web Page Generation in RESTEasy | |
| CVE-2016-6334 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbi… | |
| CVE-2016-6333 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrar… | |
| CVE-2016-5761 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email. | |
| CVE-2016-5760 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or… | |
| CVE-2016-4849 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbitrary web script or HTML by leveraging use of the COM_getCurrentURL function in… | |
| CVE-2016-4847 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex. | |
| CVE-2016-4875 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 fo… | |
| CVE-2016-4068 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnera… | |
| CVE-2016-2104 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the p… | |
| CVE-2016-1915 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale pa… | |
| CVE-2016-6348 | medium | 6.1 | 6.1 | 9y ago | JacksonJsonpInterceptor susceptible to cross-site script inclusion (XSSI) attack | |
| CVE-2016-4897 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690. | |
| CVE-2016-4892 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| CVE-2016-2803 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML. | |
| CVE-2016-1179 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTM… | |
| CVE-2016-8719 | medium | 6.1 | 6.1 | 9y ago | An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multi… | |
| CVE-2016-5682 | medium | 6.1 | 6.1 | 9y ago | Cross-Site Scripting in swagger-ui | |
| CVE-2016-5078 | medium | 6.1 | 6.1 | 9y ago | Paessler PRTG before 16.2.24.4045 has XSS via SNMP. | |
| CVE-2016-5077 | medium | 6.1 | 6.1 | 9y ago | Netikus EventSentry before 3.2.1.44 has XSS via SNMP. | |
| CVE-2016-5075 | medium | 6.1 | 6.1 | 9y ago | CloudView NMS before 2.10a has XSS via a TELNET login. | |
| CVE-2016-5073 | medium | 6.1 | 6.1 | 9y ago | CloudView NMS before 2.10a has XSS via SNMP. | |
| CVE-2016-5055 | medium | 6.1 | 6.1 | 9y ago | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page. | |
| CVE-2016-4334 | medium | 6.1 | 6.1 | 9y ago | Jive before 2016.3.1 has an open redirect from the external-link.jspa page. | |
| CVE-2016-1000307 | medium | 6.1 | 6.1 | 9y ago | Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occu… | |
| CVE-2016-10316 | medium | 6.1 | 6.1 | 9y ago | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to condu… | |
| CVE-2016-10315 | medium | 6.1 | 6.1 | 9y ago | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to condu… | |
| CVE-2016-8789 | medium | 6.1 | 6.1 | 9y ago | Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malici… | |
| CVE-2016-9990 | medium | 6.1 | 6.1 | 9y ago | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea… | |
| CVE-2016-6209 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Nagios. | |
| CVE-2016-6846 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 befor… | |
| CVE-2016-9466 | medium | 6.1 | 6.1 | 9y ago | Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the N… | |
| CVE-2016-9459 | medium | 6.1 | 6.1 | 9y ago | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is… | |
| CVE-2016-9169 | medium | 6.1 | 6.1 | 9y ago | A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScr… | |
| CVE-2016-5756 | medium | 6.1 | 6.1 | 9y ago | Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack us… | |
| CVE-2016-5751 | medium | 6.1 | 6.1 | 9y ago | An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentica… | |
| CVE-2016-4930 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions. | |
| CVE-2016-8855 | medium | 6.1 | 6.1 | 9y ago | Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or … | |
| CVE-2016-0770 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web scr… | |
| CVE-2016-8019 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated remote attackers to inject arbitrary web script o… | |
| CVE-2016-8011 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site. | |
| CVE-2016-9723 | medium | 6.1 | 6.1 | 9y ago | IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to … | |
| CVE-2016-9693 | medium | 6.1 | 6.1 | 9y ago | IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicio… | |
| CVE-2016-7140 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to inject arbitrary web… | |
| CVE-2016-7139 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web sc… | |
| CVE-2016-7138 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web… | |
| CVE-2016-4948 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a t… | |
| CVE-2016-4946 | medium | 6.1 | 6.1 | 9y ago | Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in th… | |
| CVE-2016-9148 | medium | 6.1 | 6.1 | 9y ago | Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM para… |