16,510 vulnerabilities published in 2018
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exp
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is m
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script conte
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that h
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potent
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This resul
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, res
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames
A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting i
Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume t
A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operatio
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume tha
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Andro
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed eviden
Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume t
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This result
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues inclu
SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided Java
The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search paramete
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parame
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.
acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demon
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, a
NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old pas
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a c
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verifica
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow a
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonst
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.ph
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitra
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential inform
Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confiden
Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassw
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10,
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 al
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was m
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide T
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started