16,510 vulnerabilities published in 2018
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Laun
Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent:
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: SQR). S
Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (sub
IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspec
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote att
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visib
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.j
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, le
Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resou
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parame
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to c
Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An
Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Cli
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was po
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled searc
Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A loca
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directo
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow u
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware ver
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to con
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arb
NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over use
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096.
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Aff
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface c
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The ap
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the s
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of
WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user suppl
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started