16,510 vulnerabilities published in 2018
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favori
WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in al
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross Site Scripting (XSS) vulnerability in Boxes that can result in JS
A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a sto
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to e
An issue was discovered CMS MaeloStore V.1.5.0. There is stored XSS in the Telephone field of the admin interface.
An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `F
An XSS issue was discovered in Inhaltsprojekte in Weblication CMS Core & Grid v12.6.24. The vulnerability is located in
setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /
ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could l
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a s
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /
NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devic
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administ
In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client cer
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/trans
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_di
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.
Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen.
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra
Cross-site scripting vulnerability in EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC
Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new.
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content fi
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started