16,510 vulnerabilities published in 2018
install-g-test downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Wher
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the spe
ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A spe
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack.
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, ca
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attac
The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump pri
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated.
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing att
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar
An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s
In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x befor
389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persisten
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of
PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which m
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentic
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow w
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows u
IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to pro
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environment
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the fai
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for exampl
A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a st
"Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not v
The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). The supported version that is affecte
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicke
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pk
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started