16,510 vulnerabilities published in 2018
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter valu
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a u
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has a
The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 S
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsist
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first ar
call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 tha
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a dire
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow
Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes i
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configu
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they h
In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due
react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is ge
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client c
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monit
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive inform
easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to t
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o fo
dasafio is a web server. dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the f
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin
When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the
An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leaka
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is starte
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attac
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the add
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected,
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other
On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will ha
WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security che
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake ad
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started