16,510 vulnerabilities published in 2018
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to pr
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authentic
IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to
IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows
Vulnerability in the PeopleSoft Enterprise Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Applic
Vulnerability in the Oracle Endeca Information Discovery Integrator component of Oracle Fusion Middleware (subcomponent:
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been dis
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Softw
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID inste
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input a
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as d
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users
An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabilit
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 throu
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG elem
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerabi
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements
tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which i
tianti 2.3 has stored XSS in the article management module via an article title.
tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter.
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remot
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED elemen
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter.
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter.
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Feder
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started