16,510 vulnerabilities published in 2018
In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name t
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. S
Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllAr
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET L
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Window
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The s
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account i
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass
Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV
Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerabil
coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in
Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' page
An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad q
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information
Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00;
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-r
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validati
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar wh
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi path
Directory traversal in Jester web framework 0.2.0 allows remote attackers to fetch files in arbitrary locations via "..%
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OLE objects, aka "Word
Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter. The crafted UDP
A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is i
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches runn
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intende
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory trave
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started