17,305 vulnerabilities published in 2019
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3
A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Ma
A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior t
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).
cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin wi
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens a
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly form
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feat
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset accoun
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name fi
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability na
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other peop
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to
Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploite
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
Cognitoys Dino devices allow profiles_add.html CSRF.
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started