16,510 vulnerabilities published in 2018
There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java bi
The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double
An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade thir
An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously craf
An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade thi
An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code sign
An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing che
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL
On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-cli
A stack-based buffer overflow can occur in fastboot from all Android releases(Android for MSM, Firefox OS for MSM, QRD A
In the WCD CPE codec, a Use After Free condition can occur in all Android releases(Android for MSM, Firefox OS for MSM,
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability i
If userspace provides a too-large WPA RSN IE length in wlan_hdd_cfg80211_set_ie(), a buffer overflow occurs in all Andro
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-mana
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file t
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cb3, triggered when the user opens a malformed JPEG file t
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d6a, triggered when the user opens a malformed JPEG file t
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d7d, triggered when the user opens a malformed JPEG file t
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cc4, triggered when the user opens a malformed JPEG file t
FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578dd8, triggered when the user opens a malformed JPEG file t
FastStone Image Viewer 6.2 has a User Mode Read and Execute AV at 0x0057898e, triggered when the user opens a malformed
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-inj
A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authe
A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a comm
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local
ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used a
Untrusted search path vulnerability in the installer of FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.13.0 and ea
Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL i
Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a T
Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in
Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Tr
Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges vi
Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a T
Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows
Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges
Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an a
Untrusted search path vulnerability in axpdfium v0.01 allows an attacker to gain privileges via a Trojan horse DLL in an
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via
LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in X
netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can resu
Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can resu
Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started