16,510 vulnerabilities published in 2018
IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name in
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive informatio
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allow
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java th
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.jav
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying i
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before vers
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other u
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.j
A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in Confluenc
Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorizatio
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitiv
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Directo
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which coul
A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests, aka "Microsoft
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Ex
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing V
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to sh
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization token
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is dis
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a rep
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malici
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access contro
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.j
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php.
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leadi
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts
Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potential
Insufficient data validation in Chromecast plugin in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to in
Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenS
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to suppl
An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with ad
An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possibl
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReport
IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication me
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-pu
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in M
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP softwar
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started