17,305 vulnerabilities published in 2019
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious imp
There is an information leak vulnerability in Huawei smart speaker Myna. When the smart speaker is paired with the cloud
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
Katello has multiple XSS issues in various entities
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb
OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on ro
OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI
SALTO ProAccess SPACE 5.4.3.0 allows XSS.
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields tha
GitBook through 2.6.9 allows XSS via a local .md file.
Katello: Username in Notification page has cross site scripting
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic f
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condi
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerab
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to emb
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request,
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-
IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary
SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScr
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthoriz
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. A
The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker t
The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable t
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permis
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read per
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, r
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a st
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a diffe
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An att
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visual
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a ref
IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing s
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit
File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp dir
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an exis
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started