16,510 vulnerabilities published in 2018
An information disclosure vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Androi
An information disclosure vulnerability in the Qualcomm SPMI driver. Product: Android. Versions: Android kernel. Android
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseP
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NTPD). The supported version
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary file
In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improp
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data wi
Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal"
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "so
The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow v
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively smal
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insuffic
A null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause th
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the appli
Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an int
The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if
A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-afte
An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openj
An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may
A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacke
P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create ar
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view we
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals)
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which the
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offse
Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in m
Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user
SCCP (Signalling Connection Control Part) module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Window
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
Addresses denial of service attack to eDirectory versions prior to 9.1.
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive informati
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions
jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the age
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentic
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biom
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests.
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported vers
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manife
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started