Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

16,510 results · Page 14/331
9.8
CVE-2018-9148

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it e

9.8
CVE-2018-3822

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonic

9.8
CVE-2017-14876

In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter pa

9.8
CVE-2017-14877

While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL comma

9.8
CVE-2017-14881

While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android

9.8
CVE-2017-14883

In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android be

9.8
CVE-2017-16614

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, at

9.8
CVE-2017-17766

In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of

9.8
CVE-2015-9259

In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files,

9.8
CVE-2018-9160

SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.

9.8
CVE-2018-9161

Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the

9.8
CVE-2018-9162

Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.

9.8
CVE-2018-9174

sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, b

9.8
CVE-2018-9175

DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_ma

9.8
CVE-2016-8717

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running fi

9.8
CVE-2018-1295

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/d

9.8
CVE-2018-9127

Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as v

9.8
CVE-2018-9230

In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args func

9.8
CVE-2018-4105

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "APFS" compo

9.8
CVE-2018-4108

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Manage

9.8
CVE-2018-4110

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" compone

9.8
CVE-2018-4115

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS b

9.8
CVE-2018-4124

An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Upda

9.8
CVE-2018-4148

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" compo

9.8
CVE-2018-4164

An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involv

9.8
CVE-2017-18147

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern

9.8
CVE-2018-3596

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern

9.8
CVE-2018-3599

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kern

9.8
CVE-2018-3641

Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a

9.8
CVE-2018-9247

The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execu

9.8
CVE-2018-9248

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

9.8
CVE-2018-9249

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScr

9.8
CVE-2017-13267

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This cou

9.8
CVE-2017-13274

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could le

9.8
CVE-2017-13281

In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check

9.8
CVE-2017-13282

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check

9.8
CVE-2017-13283

In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a miss

9.8
CVE-2017-13284

In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper inp

9.8
CVE-2017-13285

In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitiali

9.8
CVE-2017-13292

In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bounds check. This cou

9.8
CVE-2017-13266

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This cou

9.8
CVE-2017-13272

In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to

9.8
CVE-2018-6873

The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated

9.8
CVE-2014-9953

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

9.8
CVE-2014-9954

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

9.8
CVE-2014-9955

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

9.8
CVE-2014-9956

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

9.8
CVE-2014-9957

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

9.8
CVE-2014-9958

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

9.8
CVE-2014-9959

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel

Scan for 2018 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started