16,510 vulnerabilities published in 2018
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. P
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in o
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, loca
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the p
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.2
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of ci
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, an
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access t
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access t
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 a
A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, loca
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers a
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allow
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requir
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-pr
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could al
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing t
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated,
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Co
Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x /
Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Back Office). Supported vers
A vulnerability in the configuration and monitoring service of the Cisco SD-WAN Solution could allow an authenticated, l
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processe
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated,
The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vu
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an
Escalation of privilege in Installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user
Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to pote
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute comma
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute comma
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access t
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attac
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker
A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services
A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services
The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and
IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileg
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started