| CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
weakness |
weakness/CWE-79 |
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page |
| CWE-790 — Improper Filtering of Special Elements |
weakness |
weakness/CWE-790 |
The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a dow |
| CWE-791 — Incomplete Filtering of Special Elements |
weakness |
weakness/CWE-791 |
The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream comp |
| CWE-792 — Incomplete Filtering of One or More Instances of Special Elements |
weakness |
weakness/CWE-792 |
The product receives data from an upstream component, but does not completely filter one or more instances of special elements before sendin |
| CWE-793 — Only Filtering One Instance of a Special Element |
weakness |
weakness/CWE-793 |
The product receives data from an upstream component, but only filters a single instance of a special element before sending it to a downstr |
| CWE-794 — Incomplete Filtering of Multiple Instances of Special Elements |
weakness |
weakness/CWE-794 |
The product receives data from an upstream component, but does not filter all instances of a special element before sending it to a downstre |
| CWE-795 — Only Filtering Special Elements at a Specified Location |
weakness |
weakness/CWE-795 |
The product receives data from an upstream component, but only accounts for special elements at a specified location, thereby missing remain |
| CWE-796 — Only Filtering Special Elements Relative to a Marker |
weakness |
weakness/CWE-796 |
The product receives data from an upstream component, but only accounts for special elements positioned relative to a marker (e.g. 'at the b |
| CWE-797 — Only Filtering Special Elements at an Absolute Position |
weakness |
weakness/CWE-797 |
The product receives data from an upstream component, but only accounts for special elements at an absolute position (e.g. 'byte number 10') |
| CWE-798 — Use of Hard-coded Credentials |
weakness |
weakness/CWE-798 |
The product contains hard-coded credentials, such as a password or cryptographic key. |
| CWE-799 — Improper Control of Interaction Frequency |
weakness |
weakness/CWE-799 |
The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming reques |
| CVE-2012-0767 — Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2012-0767 |
Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML. |
| CVE-2013-5223 — D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability |
cve |
cve/CVE-2013-5223 |
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary w |
| CVE-2014-2120 — Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2014-2120 |
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability all |
| CVE-2018-6882 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2018-6882 |
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary |
| CVE-2019-3929 — Crestron Multiple Products Command Injection Vulnerability |
cve |
cve/CVE-2019-3929 |
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker c |
| CVE-2019-6693 — Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability |
cve |
cve/CVE-2019-6693 |
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS con |
| CVE-2019-9978 — WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2019-9978 |
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerabilit |
| CVE-2020-3580 — Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2020-3580 |
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-s |
| CVE-2020-8657 — EyesOfNetwork Use of Hard-Coded Credentials Vulnerability |
cve |
cve/CVE-2020-8657 |
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacke |
| CVE-2021-1879 — Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2021-1879 |
Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when process |
| CVE-2023-5631 — Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability |
cve |
cve/CVE-2023-5631 |
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript c |
| CVE-2024-3272 — D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability |
cve |
cve/CVE-2024-3272 |
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command i |
| CVE-2018-19943 — QNAP NAS File Station Cross-Site Scripting Vulnerability |
cve |
cve/CVE-2018-19943 |
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. |
| CVE-2018-19953 — QNAP NAS File Station Cross-Site Scripting Vulnerability |
cve |
cve/CVE-2018-19953 |
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. |