16,510 vulnerabilities published in 2018
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) val
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An atta
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart
Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Internal Operatio
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of D
A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI.
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authen
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD,
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipu
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure di
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (
In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to l
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated
Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modify
Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker c
A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authentic
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain mode
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorPara
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community
Vulnerability in the Oracle Communications Order and Service Management component of Oracle Communications Applications
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: HT
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager co
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to exec
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allow
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attac
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attac
A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attac
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_
Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass access restriction to access and write non-publi
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would al
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical
Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Database). Supported version
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent:
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with acc
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing
An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/temp
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started