• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-10944

February 26, 2023 by

HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.

CVE-2020-10946

February 26, 2023 by

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-10819

February 26, 2023 by

Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.

CVE-2020-10820

February 26, 2023 by

Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.

CVE-2020-10821

February 26, 2023 by

Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.

CVE-2020-10776

February 26, 2023 by

A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 925
  • Go to page 926
  • Go to page 927
  • Go to page 928
  • Go to page 929
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE