17,305 vulnerabilities published in 2019
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. Th
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in C
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in Com
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess
invenio-records before 1.2.2 allows XSS.
invenio-communities before 1.0.0a20 allows XSS.
Dependency-Track before 3.5.1 allows XSS.
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of t
Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inje
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during c
Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross
Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging.
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a val
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3
A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Ma
A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started