16,510 vulnerabilities published in 2018
IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.
PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to C
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/pars
Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XS
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS r
A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authentica
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of inte
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of inte
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, whi
Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By pe
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 serv
A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java,
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a s
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) pr
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to injec
ShowDoc v1.8.0 has XSS via a new page.
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to i
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, whi
An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vu
An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_f
An XSS issue was discovered in CremeCRM 1.6.12. It is affected by 10 stored Cross-Site Scripting (XSS) vulnerabilities i
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec
Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage u
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat
An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulne
An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started