Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

17,305 results · Page 298/347
5.4
CVE-2019-7944

A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2

5.4
CVE-2019-7945

A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior t

5.4
CVE-2016-10767

cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).

5.4
CVE-2016-10774

cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).

5.4
CVE-2017-18471

cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).

5.4
CVE-2017-18473

cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).

5.4
CVE-2017-18481

cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).

5.4
CVE-2019-14546

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending

5.4
CVE-2019-14547

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin wi

5.4
CVE-2019-14548

An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens a

5.4
CVE-2019-14549

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly form

5.4
CVE-2019-14550

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feat

5.4
CVE-2019-14668

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction

5.4
CVE-2019-14669

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset accoun

5.4
CVE-2019-14670

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name fi

5.4
CVE-2019-14672

Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability na

5.4
CVE-2016-10776

cPanel before 60.0.25 allows stored XSS during the homedir removal phase of WHM Account termination (SEC-174).

5.4
CVE-2016-10777

cPanel before 60.0.25 allows self XSS in WHM Tweak Settings for autodiscover_host (SEC-177).

5.4
CVE-2016-10778

cPanel before 60.0.25 allows self stored XSS in the listftpstable API (SEC-178).

5.4
CVE-2016-10779

cPanel before 60.0.25 allows stored XSS in api1_listautoresponders (SEC-179).

5.4
CVE-2016-10780

cPanel before 60.0.25 allows stored XSS in the ftp_sessions API (SEC-180).

5.4
CVE-2016-10781

cPanel before 60.0.25 allows self XSS in the UI_confirm API (SEC-180).

5.4
CVE-2016-10782

cPanel before 60.0.25 allows self stored XSS in postgres API1 listdbs (SEC-181).

5.4
CVE-2016-10783

cPanel before 60.0.25 allows self stored XSS in SSL_listkeys (SEC-182).

5.4
CVE-2016-10784

cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).

5.4
CVE-2019-12950

An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible

5.4
CVE-2019-14731

An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other peop

5.4
CVE-2016-10806

cPanel before 57.9999.54 allows self XSS on the Paper Lantern Landing Page (SEC-110).

5.4
CVE-2019-10373

A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to

5.4
CVE-2019-10374

A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to

5.4
CVE-2019-11653

Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploite

5.4
CVE-2019-14748

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl

5.4
CVE-2019-14221

1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.

5.4
CVE-2017-18485

Cognitoys Dino devices allow profiles_add.html CSRF.

5.4
CVE-2019-14785

The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a

5.4
CVE-2019-14787

The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newslette

5.4
CVE-2019-14792

The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity

5.4
CVE-2019-14796

The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows X

5.4
CVE-2019-14797

The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.

5.4
CVE-2019-5398

A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.

5.4
CVE-2018-20827

The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript

5.4
CVE-2019-14948

The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.

5.4
CVE-2019-14945

The ultimate-member plugin before 2.0.54 for WordPress has XSS.

5.4
CVE-2019-14946

The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.

5.4
CVE-2019-14947

The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.

5.4
CVE-2019-0334

When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it

5.4
CVE-2019-0340

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to

5.4
CVE-2019-1203

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall

5.4
CVE-2019-1218

A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An

5.4
CVE-2019-3418

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due t

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started