Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

16,510 results · Page 250/331
6.1
CVE-2018-17588

AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

6.1
CVE-2018-17589

AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

6.1
CVE-2018-17590

AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

6.1
CVE-2018-17591

AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

6.1
CVE-2018-17593

AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

6.1
CVE-2018-17594

AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

6.1
CVE-2018-17595

In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /ba

6.1
CVE-2018-17596

In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do

6.1
CVE-2018-17884

XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via th

6.1
CVE-2018-17946

The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Gallerye

6.1
CVE-2018-17947

The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter.

6.1
CVE-2018-1793

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulne

6.1
CVE-2018-1794

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vuln

6.1
CVE-2018-16050

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There

6.1
CVE-2018-17053

Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows

6.1
CVE-2018-17054

Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows

6.1
CVE-2018-17876

A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.

6.1
CVE-2018-16326

PHP Scripts Mall Olx Clone 3.4.2 has XSS.

6.1
CVE-2018-16453

PHP Scripts Mall Domain Lookup Script 3.0.5 allows XSS in the search bar.

6.1
CVE-2018-16455

PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword.

6.1
CVE-2018-16456

PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has

6.1
CVE-2018-1795

IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulner

6.1
CVE-2018-0444

A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthe

6.1
CVE-2018-0450

A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticate

6.1
CVE-2018-0452

A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an unauthenticated, remot

6.1
CVE-2018-0458

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthentica

6.1
CVE-2018-0465

A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an

6.1
CVE-2018-0480

A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent att

6.1
CVE-2018-15400

A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an unauthenticat

6.1
CVE-2018-15406

A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attac

6.1
CVE-2018-15434

A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticat

6.1
CVE-2018-15436

A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco We

6.1
CVE-2015-9273

The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via

6.1
CVE-2018-17441

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser

6.1
CVE-2018-17443

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS

6.1
CVE-2018-18069

process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_fil

6.1
CVE-2018-2470

In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do

6.1
CVE-2018-2472

SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently e

6.1
CVE-2018-18082

XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=

6.1
CVE-2018-17866

Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User

6.1
CVE-2018-18198

The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is

6.1
CVE-2018-18199

Mediamanager in REDAXO before 5.6.4 has XSS.

6.1
CVE-2018-8006

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console

6.1
CVE-2018-18207

Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.

6.1
CVE-2018-18208

Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.

6.1
CVE-2018-18209

XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.

6.1
CVE-2018-18210

XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.

6.1
CVE-2018-0057

On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP

6.1
CVE-2018-17337

Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.

6.1
CVE-2018-17784

Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic

Scan for 2018 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started