16,510 vulnerabilities published in 2018
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper acc
Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Integra
A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be af
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D.
An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9
Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.
The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vul
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow di
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x bef
Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection S
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full a
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phish
The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Manag
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading o
The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This all
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cis
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authent
IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write acc
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. P
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in o
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, loca
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the p
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.2
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of ci
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, an
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access t
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access t
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 a
A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, loca
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers a
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allow
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requir
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-pr
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could al
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing t
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated,
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started