16,510 vulnerabilities published in 2018
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTT
An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT
A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Fi
Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Suppor
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments /
Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration). Supported ve
Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Web interface). Supported version
Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: Outcome-Res
Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Overview Page/Re
Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Dashboard). S
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: None). Supported ve
Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Sup
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: None). Supported
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4,
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.
A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email addres
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow atta
The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequen
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when pr
A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handl
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: E
Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Outlook Client). Supported version
Vulnerability in the Oracle Financial Services Balance Sheet Planning component of Oracle Financial Services Application
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Platform).
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Vulnerability in the Oracle Hospitality Labor Management component of Oracle Hospitality Applications (subcomponent: Web
Vulnerability in the Oracle Financial Services Profitability Management component of Oracle Financial Services Applicati
Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent:
Vulnerability in the Oracle Financial Services Liquidity Risk Management component of Oracle Financial Services Applicat
Vulnerability in the Oracle Financial Services Price Creation and Discovery component of Oracle Financial Services Appli
Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applica
Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component of Oracle Financial Serv
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Servic
Vulnerability in the Oracle Financial Services Market Risk component of Oracle Financial Services Applications (subcompo
Vulnerability in the Oracle Financial Services Market Risk Measurement and Management component of Oracle Financial Serv
Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Services Application
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote suppor
A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of bloc
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to pe
An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e101
An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit
An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e10157
An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e10
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started