16,510 vulnerabilities published in 2018
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker ex
An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with s
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions wit
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-bas
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when
A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) wi
Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct reques
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specia
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could allow an unauthenticat
A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, r
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an un
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log f
Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/tex
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer derefere
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (re
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cpl
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger exce
The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20
The approveAndCallcode function of a smart contract implementation for Block 18 (18T), an tradable Ethereum ERC20 token,
The buy function of a smart contract implementation for Gold Reward (GRX), an Ethereum ERC20 token, allows a potential t
The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a pot
The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, all
The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a pot
The sell function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, allows a po
The sell function of a smart contract implementation for SEC, a tradable Ethereum ERC20 token, allows a potential trap t
The mintToken function of a smart contract implementation for PolyAI (AI), a tradable Ethereum ERC20 token, has no perio
The mintToken function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, has no
The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token
The mintToken function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, has no
The mintToken function of a smart contract implementation for Fujinto (NTO), a tradable Ethereum ERC20 token, has no per
The mintToken function of a smart contract implementation for GOAL Bonanza (GOAL), a tradable Ethereum ERC20 token, has
The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no pe
Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earli
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web app
SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inve
IIJ SmartKey App for Android version 2.1.0 and earlier allows remote attackers to bypass authentication [effect_of_bypas
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC261
WP ULike version 2.8.1, 3.1 contains a Incorrect Access Control vulnerability in AJAX that can result in allows anybody
ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started