16,510 vulnerabilities published in 2018
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may
A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacke
P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create ar
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view we
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals)
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which the
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offse
Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in m
Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user
SCCP (Signalling Connection Control Part) module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Window
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
Addresses denial of service attack to eDirectory versions prior to 9.1.
IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive informati
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions
jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the age
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentic
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biom
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests.
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported vers
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manife
IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they
A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Ed
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 -
IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST
An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause a
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain
An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Win
An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Win
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported version
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacke
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to d
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful auth
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks w
NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack.
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Core / Client). Supported versions tha
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access sensitive data ab
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the h
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started