16,510 vulnerabilities published in 2018
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algo
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres
An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can b
Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote
Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n
Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fail during an attack.
In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCo
In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c,
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an I
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit
augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malic
uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote
Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticate
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that cou
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDe
A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildSc
A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPo
A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifie
A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanD
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write th
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and a
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. Safari before 11.1.1 is affected. The issue involves the "Safari" com
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The is
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Messages" compon
The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via t
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (
During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire
A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pi
A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressba
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image ca
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoo
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home p
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started