16,510 vulnerabilities published in 2018
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownload
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 a
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or Jav
An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthen
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj
Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.ph
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its sear
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary we
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the tex
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Vulnerability in the Oracle Communications Order and Service Management component of Oracle Communications Applications
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supporte
Vulnerability in the Oracle Financial Services Balance Sheet Planning component of Oracle Financial Services Application
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that
Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Worklist). Supp
Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Co
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime S
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime S
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Serv
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcompone
Vulnerability in the Oracle Financial Services Profitability Management component of Oracle Financial Services Applicati
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: L
Vulnerability in the Oracle Financial Services Liquidity Risk Management component of Oracle Financial Services Applicat
Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applica
Vulnerability in the Application Express component of Oracle Database Server. The supported version that is affected is
Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component of Oracle Financial Serv
Vulnerability in the Oracle Financial Services Market Risk component of Oracle Financial Services Applications (subcompo
Vulnerability in the Oracle Financial Services Market Risk Measurement and Management component of Oracle Financial Serv
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Servic
Vulnerability in the Oracle Financial Services Price Creation and Discovery component of Oracle Financial Services Appli
Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Services Application
Vulnerability in the Oracle Financial Services Analytical Applications Reconciliation Framework component of Oracle Fina
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to re
A vulnerability in the web-based management interface of Cisco WAP150 Wireless-AC/N Dual Radio Access Point with Power o
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inj
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started