16,510 vulnerabilities published in 2018
Vulnerability in the Hardware Management Pack component of Oracle Sun Systems Products Suite (subcomponent: Ipmitool). T
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Support
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management inte
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send ema
The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if th
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons o
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this
jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SS
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device d
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allo
IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checks
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contac
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed i
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Utility). The supported version that is affected
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Sound). The supported version that is affected i
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumer
IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an a
A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All ve
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute
Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates,
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclos
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentic
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verificati
A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.
NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnera
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) bef
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.4
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allo
The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocompl
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discover
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletio
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log f
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connecti
The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwo
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker c
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD)
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on t
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitiv
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started