16,510 vulnerabilities published in 2018
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6;
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client informa
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this in
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS befor
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1,
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1,
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
S12700 V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R007C20, V200R008C00, V200R008C06, V200R009C
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in I
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Interne
An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka
An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd servi
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an acce
Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title
Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes th
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Home
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are aff
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Logging). The
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthen
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attack
A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauth
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational D
IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational D
Huawei AppGallery versions before 8.0.4.301 has a whitelist mechanism bypass vulnerability. An attacker may set up a mal
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide inf
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remov
IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details t
A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Q
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Micros
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that all
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vuln
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote auth
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. The
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started