16,510 vulnerabilities published in 2018
autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result i
The build package before 20171128 did not check directory names during extraction of build results that allowed untruste
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through
A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director c
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-mi
An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implem
An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implem
An exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP s
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi
A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extract
An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-co
Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Sam
An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsu
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extract
An exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's HTTP server of Samsun
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in video-core's HTTP
An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 -
An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsun
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm
An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of vide
An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsun
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which
A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to adm
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by
Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component result
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote a
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in u
Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to c
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started