16,510 vulnerabilities published in 2018
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_
A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance
A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsin
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The informatio
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to acce
In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially cr
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses
An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an
A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high C
A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service wh
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes mult
On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLease
Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subco
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Supported versions that
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). S
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performanc
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). Th
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported ver
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Support Cart). Supp
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments /
Vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware (subcomponent: WebCenter Spaces Appli
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). The supported version
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported ve
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones). The supported
A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specif
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticate
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 1
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message
The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to
chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against a
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remo
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive ph
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provi
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file passwo
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that co
A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic
The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive info
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started