16,510 vulnerabilities published in 2018
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache",
WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject script
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing th
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. Thi
If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can res
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. Thi
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirec
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with
A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances,
A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash,
If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbi
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime v
An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usag
An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/
An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / Proton
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the g
All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of se
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Servic
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multi
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfe
The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses speci
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received
An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated a
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /p
tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, gener
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication a
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started