16,510 vulnerabilities published in 2018
In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.p
An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.ph
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.
LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadT
In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Re
The callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 a
Winmail Server through 6.2 allows remote code execution by authenticated users who leverage directory traversal in a net
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated p
An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give
Stack-based buffer overflow in the ej_update_variables function in router/httpd/web.c on ASUS routers (when using softwa
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core T
Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Diagnostic Assistant). The suppo
Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Diagnostic Assistant). The suppo
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent:
A vulnerability in the web management GUI of the Cisco D9800 Network Transport Receiver could allow an authenticated, re
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to e
In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attacke
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 an
Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Catego
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enter
This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Ente
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of Ne
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of Ne
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for exa
Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, all
Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build proce
Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, all
Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process
Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process
Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vu
Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, result
Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute ma
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbi
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started