17,305 vulnerabilities published in 2019
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notificatio
SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which a
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not suff
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not suffi
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Internal Operations).
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?ac
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?act
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?act
Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Loa
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allo
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthen
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Cu
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the
There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Seque
totemodata 3.0.0_b936 has XSS via a folder name.
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG elemen
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable t
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, cau
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by im
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 a
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inj
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started