16,510 vulnerabilities published in 2018
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not
A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily spe
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability t
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SEC
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkin
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentia
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their D
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information
Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notificatio
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.ja
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, List
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionIns
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive info
An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket
IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could all
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou
Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou
A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affec
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:"
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard in
An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclos
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unifi
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from r
Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are no
Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.
Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without a
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a si
MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view po
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Th
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Syst
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowi
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Err
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that c
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started