• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2021-38183

February 23, 2023 by

SAP NetWeaver – versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.

CVE-2021-38186

February 23, 2023 by

An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.

CVE-2021-38193

February 23, 2023 by

An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.

CVE-2021-3811

February 23, 2023 by

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

CVE-2021-38113

February 23, 2023 by

In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.

CVE-2021-3812

February 23, 2023 by

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1382
  • Go to page 1383
  • Go to page 1384
  • Go to page 1385
  • Go to page 1386
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE