17,305 vulnerabilities published in 2019
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior t
cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).
cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin wi
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens a
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly form
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feat
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset accoun
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name fi
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability na
cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).
cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).
cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).
cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).
cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).
cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).
cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).
cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other peop
cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).
A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to
A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to
Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploite
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
Cognitoys Dino devices allow profiles_add.html CSRF.
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newslette
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows X
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it
The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due t
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started