16,510 vulnerabilities published in 2018
A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, i
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in v
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta
SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username par
Path traversal vulnerability in the administrative panel in KonaKart eCommerce Platform version 8.7 and earlier could al
BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attacker
A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buff
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could a
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors in
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information
The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a lar
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute s
In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implemen
Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vect
CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when
Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified im
Buffer overflow in util/ccnl-common.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified imp
Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have u
The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leve
ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging miss
A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VP
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass
The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an un
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via u
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started