16,510 vulnerabilities published in 2018
A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affec
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:"
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard in
An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclos
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unifi
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from r
Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are no
Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.
Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without a
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a si
MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view po
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Th
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Syst
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowi
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Err
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that c
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposur
IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an auth
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in fur
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categori
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", fo
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: HT
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). The supported versi
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Construction and Engineeri
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Search
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected
Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Health Care FastPath). Suppor
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started