16,510 vulnerabilities published in 2018
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker wit
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames.
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generatio
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before fi
The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerab
A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unau
In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodec
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the L
Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field re
An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which coul
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port s
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulti
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple v
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some in
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid u
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the
In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with stat
The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/ass
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_R
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to impo
SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that requir
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system.
VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory al
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started