16,510 vulnerabilities published in 2018
FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F forma
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable t
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and
VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 b
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot d
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped i
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the ra
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of cli
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" a
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special str
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when us
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks du
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could b
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowled
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not prope
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user syste
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to th
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to writ
NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could c
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an au
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read vi
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafte
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublishe
An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabN
A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and ea
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepEx
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to a
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated,
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able
Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification S
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder
NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have bee
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17,
Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for th
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 could allow a local attacker to inject commands i
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submi
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started