Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

7,228 of 17,305 · Page 54/145
6.1
CVE-2018-20899

cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398).

6.1
CVE-2018-20900

cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).

6.1
CVE-2013-7474

Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to

6.1
CVE-2018-20901

cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).

6.1
CVE-2018-20903

cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).

6.1
CVE-2018-20910

cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).

6.1
CVE-2018-20918

cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).

6.1
CVE-2018-20919

cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).

6.1
CVE-2018-20920

cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).

6.1
CVE-2018-20921

cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).

6.1
CVE-2018-20922

cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).

6.1
CVE-2018-20923

cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).

6.1
CVE-2019-14471

TestLink 1.9.19 has XSS via the error.php message parameter.

6.1
CVE-2019-14472

Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.

6.1
CVE-2018-20928

cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).

6.1
CVE-2018-20929

cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).

6.1
CVE-2018-20948

cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).

6.1
CVE-2018-20949

cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).

6.1
CVE-2018-20950

cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).

6.1
CVE-2018-20951

cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).

6.1
CVE-2018-20953

cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).

6.1
CVE-2019-14517

pandao Editor.md 1.5.0 allows XSS via the Javascript: string.

6.1
CVE-2017-18456

cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).

6.1
CVE-2019-6968

The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflect

6.1
CVE-2019-7877

A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior

6.1
CVE-2019-7939

A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18,

6.1
CVE-2019-14653

pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.

6.1
CVE-2016-10769

cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

6.1
CVE-2017-18472

cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).

6.1
CVE-2019-11198

Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject a

6.1
CVE-2019-14667

Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in

6.1
CVE-2016-10795

cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156).

6.1
CVE-2019-14696

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

6.1
CVE-2017-18483

ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID.

6.1
CVE-2019-10372

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allow

6.1
CVE-2019-10376

A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inj

6.1
CVE-2019-14747

DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.

6.1
CVE-2019-14750

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w

6.1
CVE-2019-14769

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain bl

6.1
CVE-2019-14770

In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be craf

6.1
CVE-2019-1954

A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthentic

6.1
CVE-2019-14772

verdaccio before 3.12.0 allows XSS.

6.1
CVE-2019-12397

Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.

6.1
CVE-2018-20962

The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.

6.1
CVE-2019-14774

The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-ad

6.1
CVE-2017-18484

Cognitoys Dino devices allow XSS via the SSID.

6.1
CVE-2016-10865

The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.p

6.1
CVE-2019-14799

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

6.1
CVE-2019-14791

The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea para

6.1
CVE-2018-20858

Recommender before 2018-07-18 allows XSS.

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started