Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27852PUBLISHED: 2021-01-20A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
CVE-2021-3137PUBLISHED: 2021-01-20XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
CVE-2020-27850PUBLISHED: 2021-01-20A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
CVE-2020-27851PUBLISHED: 2021-01-20
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privile...
CVE-2020-13134PUBLISHED: 2021-01-20
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1...
User Rank: Ninja
7/27/2019 | 4:18:33 PM
With Comodo, it comes with an IPS, Firewall system that blocks the use of applications that starts up, it is a warning system that informs the user that there is something that could be considered problematic or intrusive. AVG provides another level of protection at the browser level and filesystem. Firefox with Ghostery stops tracking, NoScript (the one that looks like the snake) does not give outside users the ability to download files with scripting capability unless you tell it is ok.
All of the programs are free to use, of course, there are Pro/Prem editions but this is a good start for a small business.
Try it out, it works pretty well.
T