17,305 vulnerabilities published in 2019
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file co
SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly
index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Serve
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea
Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecti
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
Vulnerability in the Application Express component of Oracle Database Server. Supported versions that are affected are 5
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Folders, Files & At
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Serv
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. Th
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in C
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in Com
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess
invenio-records before 1.2.2 allows XSS.
invenio-communities before 1.0.0a20 allows XSS.
Dependency-Track before 3.5.1 allows XSS.
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of t
Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inje
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during c
Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross
Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging.
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a val
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started