Filtered by CWE-79
Total 41416 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-37376 1 Teradek 6 Bond, Bond 2, Bond 2 Firmware and 3 more 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
CVE-2021-37375 1 Teradek 4 Vidiu, Vidiu Firmware, Vidiu Mini and 1 more 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.
CVE-2021-37365 1 Ctparental Project 1 Ctparental 2024-11-21 6.1 Medium
CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.
CVE-2021-37330 1 Bookingcore 1 Booking Core 2024-11-21 5.4 Medium
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another user/admin views the profile and clicks to view his avatar, an XSS will trigger.
CVE-2021-37271 1 Baidu 1 Ueditor 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
CVE-2021-37267 1 Kindsoft 1 Kindeditor 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.
CVE-2021-37216 1 Qsan 4 Xn8008t, Xn8008t Firmware, Xn8024r and 1 more 2024-11-21 6.1 Medium
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
CVE-2021-37211 1 Larvata 1 Flygo 2024-11-21 5.4 Medium
The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general user’s credential to inject JavaScript and execute stored XSS attacks.
CVE-2021-37195 1 Siemens 1 Comos 2024-11-21 6.1 Medium
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS accepts arbitrary code as attachment to tasks. This could allow an attacker to inject malicious code that is executed when loading the attachment.
CVE-2021-37152 1 Sonatype 1 Nexus Repository Manager 2024-11-21 5.4 Medium
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
CVE-2021-36950 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2021-36946 1 Microsoft 2 Dynamics 365 Business Central, Dynamics Nav 2024-11-21 5.4 Medium
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-36905 1 Expresstech 1 Quiz And Survey Master 2024-11-21 5.4 Medium
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36870 1 Codecabin 1 Wp Go Maps 2024-11-21 5.5 Medium
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
CVE-2021-36832 1 Icegram 1 Icegram Engage 2024-11-21 4.8 Medium
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
CVE-2021-36827 1 Ninjaforms 1 Ninja Forms 2024-11-21 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
CVE-2021-36823 1 Cusmin 1 Absolutely Glamorous Custom Admin 2024-11-21 6.6 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.
CVE-2021-36821 1 Incsub 1 Forminator 2024-11-21 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.
CVE-2021-36805 1 Akaunting 1 Akaunting 2024-11-21 5.2 Medium
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.
CVE-2021-36803 1 Akaunting 1 Akaunting 2024-11-21 6.3 Medium
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.