16,510 vulnerabilities published in 2018
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” opti
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to ac
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter car
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker ca
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerab
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an ex
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and th
An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and passw
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to lea
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. T
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to a
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than s
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use t
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header pars
An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_pr
An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictab
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive informat
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple us
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par
A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from wi
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated atta
Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief windo
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a re
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vu
DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may al
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with
Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/Err
A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information fr
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started