16,510 vulnerabilities published in 2018
jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker acce
lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to
ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to
peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to
sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to th
tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker a
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the fi
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the fi
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled an
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: a
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a maliciou
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a m
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a mal
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths wit
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco c
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8
A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, re
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mecha
libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (applic
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software co
An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny ser
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Speech" com
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allo
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the b
The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attacker
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cl
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
A vulnerability in open build service allows remote attackers to gain access to source files even though source access i
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially
A previously installed malicious Android application with same signature-level permissions as Firefox can intercept Auth
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefo
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amoun
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started