16,510 vulnerabilities published in 2018
The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8
The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE Syste
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shel
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB te
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbi
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).
Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of
Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a
An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administr
A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior ma
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker t
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Dis
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attack
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities
QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to re
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an at
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 41076000
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a speci
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command inje
The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registr
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chro
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user i
A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software co
A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenti
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthe
A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to acces
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrad
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthe
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthe
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmd
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started