CWE-79
46,266 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,266)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ivanti Pulsesecure2Connect Secure Pulse Policy SecureNov 21, 2024 Jun 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX. |
An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX. |
An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly. |
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected. |
LOYTEC LGATE-902 6.3.2 devices allow XSS. |
1Redhat 1Cloudforms Management Engine Jun 17, 2026 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 6.0 MEDIUM· v2 A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute...Show more |
Insufficient data validation in HTML parser in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass same origin policy via a crafted HTML page. |
Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
1Zyxel 9Uag2100 Firmware Uag4100 FirmwareUag5100 Firmware+6 moreJun 17, 2026 Jun 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreJun 17, 2026 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreJun 17, 2026 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreJun 17, 2026 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI t...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreNov 21, 2024 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability vi...Show more |