16,510 vulnerabilities published in 2018
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allo
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authen
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al
assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which a
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which
A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote atta
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remot
A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authentic
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows auth
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hostin
IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dang
Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an aut
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, a
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari be
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue in
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vu
Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circ
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due t
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a p
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages du
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page sour
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used fo
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corrup
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentiall
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially expl
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerab
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injec
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to eleva
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh att
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started