16,510 vulnerabilities published in 2018
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposur
IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an auth
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in fur
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categori
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", fo
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: HT
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). The supported versi
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Construction and Engineeri
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Search
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected
Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Health Care FastPath). Suppor
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design
IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name in
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive informatio
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allow
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java th
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.jav
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying i
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before vers
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other u
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.j
A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in Confluenc
Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorizatio
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitiv
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Directo
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which coul
A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests, aka "Microsoft
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Ex
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing V
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to sh
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization token
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is dis
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started