16,510 vulnerabilities published in 2018
A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objec
A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesse
A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp a
Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead t
Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and r
A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the steal
Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attacker
In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard ac
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can
VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Wor
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are
LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.
UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow va
An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.
JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. Th
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Softw
makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possib
A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dyn
A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by foc
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for s
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) sc
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin PO
In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Re
Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that wi
User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions v
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow remote authentic
Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System v
ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.
IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations wh
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attac
An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer over-read in internalPrintf in miniz/lupn
An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d
An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d
Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile i
Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory cor
Stegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file.
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started