Filtered by CWE-79
Total 44122 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-17372 1 Sugarcrm 1 Sugarcrm 2024-11-21 5.4 Medium
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVE-2020-17364 1 Usvn 1 User-friendly Svn 2024-11-21 6.1 Medium
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
CVE-2020-17362 1 Themeinprogress 1 Nova Lite 2024-11-21 6.1 Medium
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
CVE-2020-17083 1 Microsoft 1 Exchange Server 2024-11-21 5.5 Medium
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2020-17021 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2020-17018 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2020-17006 1 Microsoft 1 Dynamics Crm 2015 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2020-17005 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2020-16847 1 Extremenetworks 1 Extreme Management Center 2024-11-21 6.1 Medium
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
CVE-2020-16632 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
CVE-2020-16608 1 Notable 1 Notable 2024-11-21 9.6 Critical
Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).
CVE-2020-16278 1 Carson-saint 1 Saint Security Suite 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
CVE-2020-16275 1 Carson-saint 1 Saint Security Suite 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
CVE-2020-16270 1 Olimpoks 1 Olimpok 2024-11-21 6.1 Medium
OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject malicious JavaScript payload to victim’s browsers in context of vulnerable applications. Executed code can be used to steal administrator’s cookies, influence HTML content of targeted application and perform phishing-related attacks. Vulnerable application used in more than 3000 organizations in different sectors from retail to industries.
CVE-2020-16266 1 Mantisbt 1 Mantisbt 2024-11-21 5.4 Medium
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).
CVE-2020-16255 1 Owncloud 1 Owncloud 2024-11-21 6.1 Medium
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
CVE-2020-16246 1 Ge 4 S2020, S2020 Firmware, S2024 and 1 more 2024-11-21 6.1 Medium
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the victim client.
CVE-2020-16242 1 Ge 4 S2020, S2020 Firmware, S2024 and 1 more 2024-11-21 6.1 Medium
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.
CVE-2020-16210 1 Redlion 4 N-tron 702-w, N-tron 702-w Firmware, N-tron 702m12-w and 1 more 2024-11-21 9.0 Critical
The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions).
CVE-2020-16206 1 Redlion 4 N-tron 702-w, N-tron 702-w Firmware, N-tron 702m12-w and 1 more 2024-11-21 9.0 Critical
The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to sensitive data on the N-Tron 702-W / 702M12-W (all versions).