Export limit exceeded: 403062 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50172 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-6561 | 1 Agora-project | 1 Agora-project | 2025-04-20 | N/A |
| XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack. | ||||
| CVE-2017-6562 | 1 Agora-project | 1 Agora-project | 2025-04-20 | N/A |
| XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack. | ||||
| CVE-2017-7855 | 1 Icewarp | 1 Server | 2025-04-20 | N/A |
| In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter. | ||||
| CVE-2017-7871 | 1 Tdm Project | 1 Tdm | 2025-04-20 | N/A |
| trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter). | ||||
| CVE-2017-7891 | 1 Sourcebans-pp Project | 1 Sourcebans-pp | 2025-04-20 | N/A |
| sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the rebanid parameter. | ||||
| CVE-2017-2092 | 1 Cybozu | 1 Garoon | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2118 | 1 Wbce | 1 Wbce Cms | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2124 | 1 Onethird | 1 Onethird Cms | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via contact.php. | ||||
| CVE-2017-2134 | 1 Uchida | 1 Assetbase | 2025-04-20 | 6.1 Medium |
| Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2135 | 1 Wp-statistics | 1 Wp Statistics | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2136 | 1 Wp Statistics | 1 Wp Statistics | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers. | ||||
| CVE-2017-2146 | 1 Cybozu | 1 Garoon | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu. | ||||
| CVE-2017-2164 | 1 N-i-agroinformatics | 1 Soy Cms | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in SOY CMS with installer 1.8.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2174 | 1 Ipa | 1 Empirical Project Monitor - Extended | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2187 | 1 3cx | 1 Live Chat | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2194 | 1 Ipa | 1 Icodechecker | 2025-04-20 | N/A |
| Cross-site scripting vulnerability in Source code security studying tool iCodeChecker allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2017-2683 | 1 Siemens | 1 Ruggedcom Network Management Software | 2025-04-20 | N/A |
| A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions. | ||||
| CVE-2017-6675 | 1 Cisco | 1 Industrial Network Director | 2025-04-20 | N/A |
| A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases: 1.1(0.176). | ||||
| CVE-2017-2644 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.x, XSS can occur via evidence of prior learning. | ||||
| CVE-2017-2645 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.x, XSS can occur via attachments to evidence of prior learning. | ||||
