17,305 vulnerabilities published in 2019
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
TestLink 1.9.19 has XSS via the error.php message parameter.
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflect
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior
A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18,
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject a
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID.
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allow
A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inj
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain bl
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be craf
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthentic
verdaccio before 3.12.0 allows XSS.
Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-ad
Cognitoys Dino devices allow XSS via the SSID.
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.p
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea para
Recommender before 2018-07-18 allows XSS.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started