16,510 vulnerabilities published in 2018
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib
When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, trigger
JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supp
A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for b
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be i
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved b
URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scri
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixe
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dyn
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If
Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 al
Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An att
system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.
xowl/request.php in Ximdex 4.0 has XSS via the content parameter.
The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.1
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-suppl
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attacke
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3),
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, cau
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute ma
library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 a
Cross-site scripting (XSS) vulnerability in templates/frontend/pages/searchResults.tpl in Public Knowledge Project (PKP)
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4
RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulner
RSA Authentication Manager Security Console, versions 8.3 P1 and earlier, contains a reflected cross-site scripting vuln
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started