14,642 vulnerabilities published in 2017
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users
IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript
IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary
IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar
IBM DOORS Next Generation (DNG/RRC) 4.07, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows
Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter.
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inje
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows re
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows us
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote a
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Devic
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW)
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string c
A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0
Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote aut
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cro
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_pro
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow re
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.
Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction requ
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria r
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of a
Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec
An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb
An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact
An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functio
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithre
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp o
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remot
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started