CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potenti...Show more |
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potenti...Show more |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 8.4 HIGH· v3 6.8 MEDIUM· v2 Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access. |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malic...Show more |
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malici...Show more |
1Ge 2S2020 Firmware S2020g FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back...Show more |
2Apple Webkitgtk7Icloud IpadosIphone Os+4 moreJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted w...Show more |
2Apple Webkitgtk2Watchos WebkitgtkJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting. |
2Apple Webkitgtk3Icloud ItunesWebkitgtkJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lea...Show more |
1Apple 6Icloud Iphone OsItunes+3 moreJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6...Show more |
2Apple Webkitgtk3Iphone Os SafariWebkitgtkJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting. |
1Apple 7Icloud Iphone OsItunes+4 moreJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Win...Show more |
1Apple 6Icloud Iphone OsItunes+3 moreJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Window...Show more |
2Apple Webkitgtk3Icloud ItunesWebkitgtkJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lea...Show more |
1Apple 5Icloud Iphone OsItunes+2 moreJun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to un...Show more |
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting. |
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting. |
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182. |
1Hp 1Oneview For Vmware Vcenter Jun 17, 2026 Dec 18, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting. |
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. |