16,510 vulnerabilities published in 2018
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in t
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint loca
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue
In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 o
In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attack
GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700
Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly san
Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web i
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthentic
ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the
The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitr
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A use-after-free can occur in _pbcM_sp_query in m
Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary comman
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag c
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and pri
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or pot
PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or po
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API r
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management S
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegi
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in
Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not ha
dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.address.php has SQL Injection via the numPerPage para
A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector pri
A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability
A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability
A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability
A Remote Bypass of Security Restrictions vulnerability was identified in HPE XP Command View Advanced Edition Software E
A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager
HPE has identified a remote privilege escalation vulnerability in HPE CentralView Fraud Risk Management earlier than ver
ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started