Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
reflected xss vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-0010
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted ...
Paloaltonetworks Pan-os
4.3
CVSSv2
CVE-2019-16521
The broken-link-checker plugin up to and including 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be ex...
Managewp Broken Link Checker
4.3
CVSSv2
CVE-2019-17092
An XSS vulnerability in project list in OpenProject prior to 9.0.4 and 10.x prior to 10.0.2 allows remote malicious users to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.
Openproject Openproject
4.3
CVSSv2
CVE-2018-14013
Synacor Zimbra Collaboration Suite Collaboration prior to 8.8.11 has XSS in the AJAX and html web clients.
Synacor Zimbra Collaboration Suite 8.7.11
Synacor Zimbra Collaboration Suite 8.8.11
Synacor Zimbra Collaboration Suite 8.8.10
Synacor Zimbra Collaboration Suite 8.8.9
Synacor Zimbra Collaboration Suite
3.5
CVSSv2
CVE-2018-19934
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
Solarwinds Serv-u Ftp Server 15.1.6.25
3.5
CVSSv2
CVE-2012-2985
Cross-site scripting (XSS) vulnerability in InsertDocument.aspx in CuteSoft Cute Editor 6.4 allows remote authenticated users to inject arbitrary web script or HTML via the _UploadID parameter.
Cutesoft Components Cute Editor 6.4
3.5
CVSSv2
CVE-2019-17207
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page via the wp-admin/tools.p...
Managewp Broken Link Checker
4.3
CVSSv2
CVE-2012-4939
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface prior to 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote malicious users to inject arbitrary web script or HTML via the "Search for an IP address" f...
Solarwinds Orion Network Performance Monitor 10.3
Solarwinds Orion Network Performance Monitor 10.2
Solarwinds Orion Network Performance Monitor 10.1.13.0
Solarwinds Orion Network Performance Monitor 10.2.2
Solarwinds Ip Address Manager Web Interface
Solarwinds Orion Network Performance Monitor -
Solarwinds Orion Network Performance Monitor 10.1
Solarwinds Orion Network Performance Monitor 10.2.1
Solarwinds Orion Network Performance Monitor 10.0
Solarwinds Orion Network Performance Monitor 10.3.1
1 EDB exploit
4.3
CVSSv2
CVE-2018-17865
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote malicious users to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Sap J2ee Engine 7.01
4.3
CVSSv2
CVE-2020-11727
A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter.
Algolplus Advanced Order Export 3.1.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »