2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19800aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
CVE-2018-19465Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php ...
CVE-2018-19462admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that...
CVE-2018-19461admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
CVE-2018-19452A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF ...
CVE-2018-19451A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-5264Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free ti...
CVE-2018-20523MEDIUM5.3Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider ...
CVE-2018-20135Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of appl...
CVE-2018-20091An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow...
CVE-2018-20014In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-6185In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undel...
CVE-2018-5798This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.
CVE-2018-5265Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credential...
CVE-2018-9839An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying...
CVE-2018-8047vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and proba...
CVE-2018-2028MEDIUM6.5IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which ...
CVE-2018-10171Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyz...
CVE-2018-7125A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio...
CVE-2018-7124A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio...
CVE-2018-7123A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ver...
CVE-2018-7122A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier ...
CVE-2018-7121A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio...
CVE-2018-18571CRITICAL9.1An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 a...
CVE-2018-13384A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a r...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now