Search Results (45743 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-37462 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
CVE-2021-37461 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
CVE-2021-37460 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
CVE-2021-37459 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
CVE-2021-37458 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
CVE-2021-37457 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
CVE-2021-37456 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
CVE-2021-37455 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
CVE-2021-37454 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
CVE-2021-37453 1 Nchsoftware 1 Axon Pbx 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
CVE-2021-37451 1 Nchsoftware 1 Ivm Attendant 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
CVE-2021-37450 1 Nchsoftware 1 Ivm Attendant 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
CVE-2021-37449 1 Nchsoftware 1 Ivm Attendant 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
CVE-2021-37448 1 Nchsoftware 1 Ivm Attendant 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
CVE-2021-37416 1 Zohocorp 1 Manageengine Adselfservice Plus 2024-11-21 6.1 Medium
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
CVE-2021-37412 1 It-economics 1 Techradar 2024-11-21 6.1 Medium
The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.
CVE-2021-37403 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
CVE-2021-37402 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
CVE-2021-37393 1 Rpcms 1 Rpcms 2024-11-21 5.4 Medium
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
CVE-2021-37392 1 Rpcms 1 Rpcms 2024-11-21 5.4 Medium
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API functions are enabled, the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.