16,510 vulnerabilities published in 2018
An issue was discovered in Rincewind 0.1. A reinstall vulnerability exists because the parameter p of index.php and anot
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integ
An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability b
The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow v
The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game,
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file para
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and wi
Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS proce
The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Ser
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queu
HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earli
A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E050
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component i
An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption
The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix Busines
An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER),
An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 t
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the devi
Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive informatio
A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensi
mingw-w64 version 5.0.4 by default produces executables that opt in to ASLR, but are not compatible with ASLR. ASLR is a
man-cgi before 1.16 allows Local File Inclusion via absolute path traversal, as demonstrated by a cgi-bin/man-cgi?/etc/p
An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access inform
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started