Search Results (47872 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-1911 1 Sap 1 Netweaver 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) Runtime Workbench (RWB) or (2) Pmitest servlet in the Process Monitoring Infrastructure (PMI), aka SAP Security Notes 2206793 and 2234918.
CVE-2016-1912 1 Dolibarr 1 Dolibarr 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.
CVE-2016-1000143 1 Photoxhibit Project 1 Photoxhibit 2025-04-12 N/A
Reflected XSS in wordpress plugin photoxhibit v2.1.8
CVE-2016-1000142 1 Parsi-font Project 1 Parsi-font 2025-04-12 N/A
Reflected XSS in wordpress plugin parsi-font v4.2.5
CVE-2016-1000140 1 New-year-firework Project 1 New-year-firework 2025-04-12 N/A
Reflected XSS in wordpress plugin new-year-firework v1.1.9
CVE-2016-1000154 1 Browserweb 1 Whizz 2025-04-12 N/A
Reflected XSS in wordpress plugin whizz v1.0.7
CVE-2016-1913 1 Redhen Project 1 Redhen 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Redhen module 7.x-1.x before 7.x-1.11 for Drupal allow remote authenticated users with certain access to inject arbitrary web script or HTML via unspecified vectors, related to (1) individual contacts, (2) notes, or (3) engagement scores.
CVE-2016-1918 1 Blackberry 1 Enterprise Server 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1917.
CVE-2016-2954 1 Ibm 1 Connections 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2956 and CVE-2016-3008.
CVE-2016-0866 1 Tollgrade 1 Smartgrid Lighthouse Sensor Management System 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-1000138 1 Indexisto Project 1 Indexisto 2025-04-12 N/A
Reflected XSS in wordpress plugin indexisto v1.0.5
CVE-2016-1000136 1 Heat-trackr Project 1 Heat-trackr 2025-04-12 N/A
Reflected XSS in wordpress plugin heat-trackr v1.0
CVE-2016-1000155 1 Wpsolr 1 Wpsolr-search-engine 2025-04-12 N/A
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
CVE-2015-8376 1 Getsymphony 1 Symphony 2025-04-12 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.
CVE-2016-1000127 1 Ajax-random-post Project 1 Ajax-random-post 2025-04-12 N/A
Reflected XSS in wordpress plugin ajax-random-post v2.00
CVE-2016-0926 1 Pivotal Software 1 Cloud Foundry Elastic Runtime 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
CVE-2016-1941 2 Apple, Mozilla 2 Mac Os X, Firefox 2025-04-12 N/A
The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
CVE-2016-1000118 1 Huge-it 1 Slideshow 2025-04-12 N/A
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-2864 1 Ibm 7 Rational Collaborative Lifecycle Management, Rational Doors Next Generation, Rational Engineering Lifecycle Manager and 4 more 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2015-3386 1 Node Access Product Project 1 Node Access Product 2025-04-12 N/A
Cross-site scripting (XSS) vulnerability in the Node Access Product module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.