Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

16,510 results · Page 311/331
4.8
CVE-2018-12431

SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).

4.8
CVE-2018-9036

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users

4.8
CVE-2018-7681

Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favori

4.8
CVE-2018-1000508

WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in al

4.8
CVE-2018-1000513

LimeSurvey version 3.0.0-beta.3+17110 contains a Cross Site Scripting (XSS) vulnerability in Boxes that can result in JS

4.8
CVE-2018-11448

A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a sto

4.8
CVE-2018-1351

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to e

4.8
CVE-2018-12992

An issue was discovered CMS MaeloStore V.1.5.0. There is stored XSS in the Telephone field of the admin interface.

4.8
CVE-2018-13000

An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `F

4.8
CVE-2018-13002

An XSS issue was discovered in Inhaltsprojekte in Weblication CMS Core & Grid v12.6.24. The vulnerability is located in

4.8
CVE-2018-1113

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /

4.8
CVE-2018-13106

ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.

4.8
CVE-2018-3763

In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could l

4.8
CVE-2018-3764

In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a s

4.8
CVE-2017-2665

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /

4.8
CVE-2018-12462

NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.

4.8
CVE-2017-16710

Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devic

4.8
CVE-2018-13998

ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.

4.8
CVE-2018-13999

Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administ

4.8
CVE-2017-7468

In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client cer

4.8
CVE-2018-13832

Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu

4.8
CVE-2018-14419

MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.

4.8
CVE-2018-10882

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/trans

4.8
CVE-2018-10883

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_di

4.8
CVE-2018-14936

The Add page option in my little forum 2.4.12 allows XSS via the Title field.

4.8
CVE-2018-14937

The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.

4.8
CVE-2018-14969

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.

4.8
CVE-2018-14970

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.

4.8
CVE-2018-14971

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.

4.8
CVE-2018-14972

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.

4.8
CVE-2018-14973

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.

4.8
CVE-2018-14974

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.

4.8
CVE-2018-14975

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.

4.8
CVE-2018-14976

An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.

4.8
CVE-2018-14837

Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.

4.8
CVE-2018-10634

Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently

4.8
CVE-2018-15570

In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.

4.8
CVE-2018-15842

WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.

4.8
CVE-2018-15843

GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.

4.8
CVE-2018-16327

There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.

4.8
CVE-2018-16346

ChemCMS 1.0.6 has XSS via the "setting -> website information" field.

4.8
CVE-2018-16348

SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.

4.8
CVE-2018-16374

Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.

4.8
CVE-2018-16379

Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen.

4.8
CVE-2018-0652

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra

4.8
CVE-2018-0655

Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra

4.8
CVE-2018-0657

Cross-site scripting vulnerability in EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC

4.8
CVE-2018-16772

Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new.

4.8
CVE-2018-16773

EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content fi

4.8
CVE-2018-16775

An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.

Scan for 2018 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started