16,510 vulnerabilities published in 2018
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command inje
The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-a
Icy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior ver
FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order param
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPre
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on ce
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Upload
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 al
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary op
Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper res
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to ad
In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.
In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenti
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via th
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via th
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data v
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary cod
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability. Due to improper privilege
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project se
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via t
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-
The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id para
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser ac
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central an
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started