16,510 vulnerabilities published in 2018
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed wit
Yosoro 1.0.4 has stored XSS.
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unaut
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '
html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled v
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can
i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from t
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angul
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cro
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scri
Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent U
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or Asci
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not esc
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vul
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerabil
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attack
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) t
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of f
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remot
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-s
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib
When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, trigger
JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supp
A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for b
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be i
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved b
URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scri
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixe
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dyn
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started