2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16988CRITICAL9.8An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak pa...
CVE-2018-16961An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the f...
CVE-2018-16960An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal...
CVE-2018-16718An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted ...
CVE-2018-16717A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.
CVE-2018-16716A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, whic...
CVE-2018-10383Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
CVE-2018-12404A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content....
CVE-2018-2015MEDIUM6.4IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers...
CVE-2018-8035This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache ...
CVE-2018-17606Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16620. Reason: This candidate is a reservation d...
CVE-2018-1933MEDIUM5.4IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2018-1608MEDIUM5.9IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that cou...
CVE-2018-20835A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball co...
CVE-2018-20834A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue ...
CVE-2018-15208BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
CVE-2018-15207BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a norm...
CVE-2018-15206BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
CVE-2018-14931An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exis...
CVE-2018-14930An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebA...
CVE-2018-14875An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists ...
CVE-2018-14874An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code pa...
CVE-2018-20510The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users...
CVE-2018-20509The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obta...
CVE-2018-19374Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Troj...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now