16,510 vulnerabilities published in 2018
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveragi
Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an ou
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execut
An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and p
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, a
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless
A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP
A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct d
Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prio
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerabilit
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers util
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have
A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and writ
Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attack
A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows pla
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and r
A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execu
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting acces
A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can
An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US
The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2
An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enable
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against mali
Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating s
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. I
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable t
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files c
In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that wi
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in wh
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM
Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt.
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started