16,510 vulnerabilities published in 2018
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single sh
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) h
Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for
An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reaso
An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storag
The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prio
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite lo
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) s
In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote a
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remo
libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRI
In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, rel
In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header functio
In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in li
In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_prof
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. Wh
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a
An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4
Improper Validation of Array Index in Multimedia While parsing an mp4 file in Snapdragon Automobile, Snapdragon Mobile a
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data
An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by snd
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.c
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an i
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could
Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation cou
A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having acces
A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or P
Buffer overflow in event handler in Intel Active Management Technology in Intel Converged Security Manageability Engine
A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UN
A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (
An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client
Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with har
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web pa
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommende
An issue has been found in libwav through 2017-04-20. It is a SEGV in the function print_info in wav_info/wav_info.c.
An issue has been found in libwav through 2017-04-20. It is a SEGV in the function wav_free in libwav.c.
An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c.
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to impr
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started