14,642 vulnerabilities published in 2017
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would ena
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storag
A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthentica
A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulne
Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation doc
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or
In ObjectPlanet Opinio before 7.6.4, there is XSS.
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x befor
Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Networ
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Networ
A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal could allow an unaut
A vulnerability in the web framework of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a c
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker
An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary we
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script
In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and
EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an open redirect vulnerability. A rem
Cross-site scripting vulnerability in Cybozu KUNAI for Android 3.0.0 to 3.0.6 allows remote attackers to inject arbitrar
Cross-site scripting vulnerability in Source code security studying tool iCodeChecker allows an attacker to inject arbit
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inje
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect us
Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web
Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitr
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_refer
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 al
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 al
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 al
FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when reg
FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the Use
In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redi
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows u
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter o
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started