16,510 vulnerabilities published in 2018
i18next is a language translation framework. When using the .init method, passing interpolation options without passing
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTM
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persisten
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitizatio
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.3
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript:
marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parse
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS)
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5
A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF valida
Hue 3.12 has XSS via the /pig/save/ name and script parameters.
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNot
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/
On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect a
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plu
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerabili
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed wit
Yosoro 1.0.4 has stored XSS.
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unaut
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '
html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled v
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from t
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angul
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cro
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scri
Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent U
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or Asci
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not esc
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vul
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerabil
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attack
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) t
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of f
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started