16,510 vulnerabilities published in 2018
The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or a
The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NI
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of a
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose
The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or
Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-
SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerabili
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-doma
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a
The printing process can bypass local access protections to read files available through symlinks, bypassing local file
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still
If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rend
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to sc
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont
Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When use
A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Cust
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission not
In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name t
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. S
Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllAr
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET L
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Window
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The s
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account i
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started