16,510 vulnerabilities published in 2018
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link sha
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of
In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check.
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the loca
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users se
A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Ve
A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 wa
A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior
A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.
A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version pr
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version pr
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attac
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an atta
A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, Ansi
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS
IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privi
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitr
A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certi
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may
A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorize
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Sec
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentia
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was fou
A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on W
IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported vers
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). The supported version
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attac
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vul
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA d
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS cr
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creat
The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of se
The Windows GDI component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulne
The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue ma
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grf
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started