16,510 vulnerabilities published in 2018
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host paramete
An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter.
An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin passwor
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER .
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-
All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to c
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses har
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses har
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 an
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 an
FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on th
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x b
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
Library Management System 1.0 has SQL Injection via the "Search for Books" screen.
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.
LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.
pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in proces
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then r
Arbitrary file upload in jQuery Upload File <= 4.0.2
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already crea
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application th
DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traf
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile
HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the u
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $
TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function us
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function us
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm
An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/
An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started