16,510 vulnerabilities published in 2018
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before pa
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could
A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrar
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords pa
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the or
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects p
An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0
A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filt
A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integra
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files t
SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted data
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vuln
The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in
A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to exec
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code f
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block
D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTom
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated a
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary P
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) versio
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippet
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php
Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstra
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a de
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjuncti
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract
A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lig
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. Thi
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell me
A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application admin
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communicatio
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default A
A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged
If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can o
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrat
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started