16,510 vulnerabilities published in 2018
A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERA
The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to a
curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with
The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back
The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading
Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar wh
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in St
Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application fold
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized u
HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier tha
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being lo
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthe
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” opti
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to ac
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter car
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker ca
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerab
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an ex
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and th
An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and passw
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to lea
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. T
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to a
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than s
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started