16,510 vulnerabilities published in 2018
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). S
Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Stylesheet
Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manage
Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from v
The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or
Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remot
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_us
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintex
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses th
Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race conditio
phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirec
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack w
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to c
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.17
The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/releas
The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any a
Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless networ
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks d
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modif
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "acco
Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerabilit
Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulner
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Files Widget" co
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Find My iPhone"
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection
Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string
Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it tra
Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card d
In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physicall
In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker
Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the ver
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Magnifier" compo
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri Contacts" c
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component.
Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to par
Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encrypt
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this
An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscree
An out-of-bounds read issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the f
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started