16,510 vulnerabilities published in 2018
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android
An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Androi
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel
IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system comma
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
authentication.cgi on D-Link DIR-868L devices with Singapore StarHub firmware before v1.21SHCb03 allows remote attackers
Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, w
An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek Neur
An exploitable code execution vulnerability exists in the SavePatientMontage functionality of Natus Xltek NeuroWorks 8.
An exploitable code execution vulnerability exists in the NewProducerStream functionality of Natus Xltek NeuroWorks 8. A
An exploitable code execution vulnerability exists in the OpenProducer functionality of Natus Xltek NeuroWorks 8. A spec
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow app
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveragi
The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow w
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execu
In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to ex
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by
LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow app
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, SD
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MS
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9607, MDM9625, MD
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started