16,510 vulnerabilities published in 2018
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it e
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonic
In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter pa
While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL comma
While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android
In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android be
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, at
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files,
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, b
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_ma
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running fi
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/d
Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as v
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args func
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "APFS" compo
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Manage
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" compone
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Upda
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" compo
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involv
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern
Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execu
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScr
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This cou
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could le
In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check
In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a miss
In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper inp
In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitiali
In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bounds check. This cou
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This cou
In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started