16,510 vulnerabilities published in 2018
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF.
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.user.php has SQL Injection via the numPerPage paramet
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01
A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collec
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users.
Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventor
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a use
ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (he
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possib
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for spe
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forg
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentia
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabili
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI
VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in
SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR befo
SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR be
SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 al
SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of Ope
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR be
SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, ak
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authentic
admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious fil
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started