16,510 vulnerabilities published in 2018
In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned a
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version
The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensiti
The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2
Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to ca
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backu
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redi
Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof t
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform d
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perfor
A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap c
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance
A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function o
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticate
The OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, all
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not
A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a
The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial o
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote t
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remo
A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID:
In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remot
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, relat
In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in
A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0
An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within
A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vul
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could en
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space
In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved
In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evalu
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to st
Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessi
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing t
Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from a
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to ob
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 201
Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL
A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all vers
A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started