16,510 vulnerabilities published in 2018
python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using
The request_dividend function of a smart contract implementation for ROC (aka Rasputin Online Coin), an Ethereum ERC20 t
The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates f
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to pla
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to pla
This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the R
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache en
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentica
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it shou
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined an
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can oft
electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with
csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail
engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-dire
uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate
On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions wit
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulner
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Wher
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the spe
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A spe
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attac
The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump pri
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated.
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing att
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar
An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s
In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x befor
389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persisten
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of
PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which m
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started