16,510 vulnerabilities published in 2018
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /ba
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via th
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Gallerye
The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter.
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulne
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vuln
An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows
A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.
PHP Scripts Mall Olx Clone 3.4.2 has XSS.
PHP Scripts Mall Domain Lookup Script 3.0.5 allows XSS in the search bar.
PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword.
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has
IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulner
A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthe
A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticate
A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an unauthenticated, remot
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthentica
A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent att
A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an unauthenticat
A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attac
A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticat
A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco We
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_fil
In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do
SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently e
XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User
The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is
Mediamanager in REDAXO before 5.6.4 has XSS.
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.
On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP
Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started