16,510 vulnerabilities published in 2018
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_di
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.
Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen.
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra
Cross-site scripting vulnerability in EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC
Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new.
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content fi
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link
A DLL injection vulnerability in the Intel IoT Developers Kit 4.0 installer may allow an authenticated user to potential
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action,
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section na
An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey,
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custo
DASAN H660GW devices have Stored XSS in the Port Forwarding functionality.
A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, remote attacker to co
A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system
Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HT
An issue was discovered in DESTOON B2B 7.0. admin\setting.inc.php has XSS via the first text box to the admin.php URI.
An issue was discovered in DESTOON B2B 7.0. XSS exists via certain text boxes to the admin.php?moduleid=2&action=add URI
An issue was discovered in DESTOON B2B 7.0. admin/category.inc.php has XSS via the category[catname] parameter to the ad
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated,
LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name par
* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x befor
admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS vi
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started