16,510 vulnerabilities published in 2018
PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface cha
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=del
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate cert
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both t
In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Ke
Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacke
Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens
SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initi
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables
In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion patt
In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibil
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections a
Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidentia
A STOP error (BSoD) in the ibtfltcoex.sys driver for Intel Centrino Wireless N and Intel Centrino Advanced N adapters ma
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Servic
A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially cr
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
In Lizard (formerly LZ5) 2.0, use of an invalid memory address was discovered in LZ5_compress_continue in lz5_compress.c
On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertio
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught
In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc.
ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code v
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured req
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/devi
wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image.
The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic:
In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of se
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "pani
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a
An information disclosure vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera runn
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started