16,510 vulnerabilities published in 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read vi
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafte
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublishe
An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabN
A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and ea
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepEx
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to a
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated,
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able
Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification S
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder
NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have bee
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17,
Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for th
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 could allow a local attacker to inject commands i
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submi
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page
PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1)
SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute craft
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confl
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Ques
A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles mult
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafte
Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftwa
An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118.
An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmw
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor o
An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of eval
my little forum 2.4.12 allows CSRF for deletion of users.
The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not alway
JerryScript version Tested on commit f86d7459d195c8ba58479d1861b0cc726c8b3793. Analysing history it seems that the issue
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of te
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started