16,510 vulnerabilities published in 2018
Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless networ
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks d
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modif
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "acco
Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerabilit
Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulner
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Files Widget" co
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Find My iPhone"
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection
Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string
Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it tra
Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card d
In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physicall
In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker
Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the ver
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Magnifier" compo
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri Contacts" c
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component.
Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to par
Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encrypt
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this
An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscree
An out-of-bounds read issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the f
Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) b
Mate10 Pro Huawei smart phones with the versions before 8.1.0.326(C00) have a FRP bypass vulnerability. During the mobil
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker wi
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physic
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers
Huawei smart phones G9 Lite, Honor 5A, Honor 6X, Honor 8 with the versions before VNS-L53C605B120CUSTC605D103, the versi
Huawei smartphones Mate10 with versions earlier before ALP-AL00B 8.0.0.110(C00) have a Factory Reset Protection (FRP) by
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others.
There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the
Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnera
Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C0
An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible
Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to im
A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLoc
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the applic
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the applic
Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: ADPatch). Supported ver
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started