16,510 vulnerabilities published in 2018
Improper verification when expanding ZIP64 archives in Lhaplus versions 1.73 and earlier may lead to unintended contents
The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /va
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local
MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parame
Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R00
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R00
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R00
Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00,
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames cont
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to g
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwor
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password,
Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could all
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could all
Huawei eNSP software with software of versions earlier than V100R002C00B510 has a buffer overflow vulnerability. Due to
Huawei ViewPoint 8660 V100R008C03 have a memory leak vulnerability. The software does not release allocated memory prope
Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V2
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microso
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restricti
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before
The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local user
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles"
An information disclosure vulnerability in the Qualcomm USB driver. Product: Android. Versions: Android kernel. Android
An information disclosure vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Androi
An information disclosure vulnerability in the Qualcomm SPMI driver. Product: Android. Versions: Android kernel. Android
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseP
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NTPD). The supported version
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary file
In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improp
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data wi
Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal"
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "so
The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow v
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively smal
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insuffic
A null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause th
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the appli
Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an int
The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if
A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-afte
An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openj
An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started