16,510 vulnerabilities published in 2018
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Logging). The
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthen
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attack
A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauth
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational D
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational D
Huawei AppGallery versions before 8.0.4.301 has a whitelist mechanism bypass vulnerability. An attacker may set up a mal
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide inf
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remov
IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details t
A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Q
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Micros
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that all
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vuln
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote auth
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. The
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not
A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily spe
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability t
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SEC
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkin
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentia
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their D
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information
Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notificatio
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.ja
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, List
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionIns
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive info
An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket
IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou
Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started