16,510 vulnerabilities published in 2018
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write th
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and a
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. Safari before 11.1.1 is affected. The issue involves the "Safari" com
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The is
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Messages" compon
The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via t
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (
During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire
A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pi
A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressba
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image ca
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoo
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home p
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbi
An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the clien
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE
The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Ad
OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (M
An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBD
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka
An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may
An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FF
libavcodec in FFmpeg 4.0 may trigger a NULL pointer dereference if the studio profile is incorrectly detected while conv
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerabi
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerabi
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a cra
An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files vi
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be perform
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-ser
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can f
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the dif
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started