Vulnerabilities (CVE)

Filtered by CWE-79
Total 47280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1000128 1 Anti-plagiarism Project 1 Anti-plagiarism 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin anti-plagiarism v3.60
CVE-2016-1000127 1 Ajax-random-post Project 1 Ajax-random-post 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin ajax-random-post v2.00
CVE-2016-1000126 1 Admin-font-editor Project 1 Admin-font-editor 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin admin-font-editor v1.8
CVE-2016-1000121 1 Huge-it 1 Slider 2026-06-17 3.5 LOW 4.8 MEDIUM
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000119 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000118 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000117 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000116 1 Huge-it 1 Portfolio Gallery Manager 2026-06-17 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000115 1 Huge-it 1 Portfolio Gallery Manager 2026-06-17 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000114 1 Huge-it 1 Gallery 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000037 2 Fedoraproject, Redhat 3 Fedora, Enterprise Linux, Pagure 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Pagure: XSS possible in file attachment endpoint
CVE-2016-1000029 1 Tenable 1 Nessus 2026-06-17 3.5 LOW 4.8 MEDIUM
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).
CVE-2016-1000028 1 Tenable 1 Nessus 2026-06-17 3.5 LOW 4.8 MEDIUM
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).
CVE-2016-1000007 1 Redhat 1 Pagure 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Pagure 2.2.1 XSS in raw file endpoint
CVE-2016-0955 4 Adobe, Apple, Linux and 1 more 4 Experience Manager, Mac Os X, Linux Kernel and 1 more 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
CVE-2016-0927 1 Pivotal Software 1 Cloud Foundry Elastic Runtime 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-0926 1 Pivotal Software 1 Cloud Foundry Elastic Runtime 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
CVE-2016-0925 1 Emc 1 Rsa Adaptive Authentication On-premise 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and 7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-0919 1 Rsa 1 Web Threat Detection 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CVE-2016-0901 1 Emc 1 Rsa Authentication Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0900.