Filtered by CWE-79
Total 41414 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-28803 1 Qnap 1 Q\'center 2024-11-21 5.4 Medium
This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.
CVE-2021-28796 1 Increments 1 Qiita\ 2024-11-21 6.1 Medium
Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.
CVE-2021-28556 1 Magento 1 Magento 2024-11-21 6.9 Medium
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
CVE-2021-28461 1 Microsoft 1 Dynamics 365 2024-11-21 6.1 Medium
Dynamics Finance and Operations Cross-site Scripting Vulnerability
CVE-2021-28459 1 Microsoft 1 Azure Devops Server 2024-11-21 6.1 Medium
Azure DevOps Server Spoofing Vulnerability
CVE-2021-28424 1 Phpgurukul 1 Teachers Record Management System 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.
CVE-2021-28420 1 Seopanel 1 Seo Panel 2024-11-21 4.8 Medium
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.
CVE-2021-28418 1 Seopanel 1 Seo Panel 2024-11-21 4.8 Medium
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.
CVE-2021-28417 1 Seopanel 1 Seo Panel 2024-11-21 4.8 Medium
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.
CVE-2021-28382 1 Zohocorp 1 Manageengine Key Manager Plus 2024-11-21 5.4 Medium
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
CVE-2021-28380 1 Aimeos Project 1 Aimeos 2024-11-21 5.4 Medium
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.
CVE-2021-28378 1 Gitea 1 Gitea 2024-11-21 3.7 Low
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
CVE-2021-28359 1 Apache 1 Airflow 2024-11-21 6.1 Medium
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.10.15 in 1.x series and affects 2.0.0 and 2.0.1 and 2.x series. This is the same as CVE-2020-13944 & CVE-2020-17515 but the implemented fix did not fix the issue completely. Update to Airflow 1.10.15 or 2.0.2. Please also update your Python version to the latest available PATCH releases of the installed MINOR versions, example update to Python 3.6.13 if you are on Python 3.6. (Those contain the fix for CVE-2021-23336 https://nvd.nist.gov/vuln/detail/CVE-2021-23336).
CVE-2021-28290 1 Identityserver4.admin Project 1 Identityserver4.admin 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
CVE-2021-28280 1 Php-fusion 1 Phpfusion 2024-11-21 6.1 Medium
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
CVE-2021-28247 1 Ca 1 Ehealth Performance Manager 2024-11-21 5.4 Medium
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The affected endpoints are: cgi/nhWeb with the parameter report, aviewbin/filtermibobjects.pl with the parameter namefilter, and aviewbin/query.pl with the parameters System, SystemText, Group, and GroupText. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2021-28161 1 Eclipse 1 Theia 2024-11-21 6.1 Medium
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
CVE-2021-28160 1 Acexy Wireless-n Wifi Repeater Project 2 Acexy Wireless-n Wifi Repeater, Acexy Wireless-n Wifi Repeater Firmware 2024-11-21 6.1 Medium
Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section).
CVE-2021-28145 1 Concretecms 1 Concrete Cms 2024-11-21 5.4 Medium
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.
CVE-2021-28126 1 Compassplus 1 Tranzware E-commerce Payment Gateway 2024-11-21 6.1 Medium
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability