2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20239MEDIUM5.4Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version...
CVE-2018-2007MEDIUM5.9IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to...
CVE-2018-2004MEDIUM5.4IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2018-1961MEDIUM5.3IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from...
CVE-2018-5123A third party website can access information available to a user with access to a restricted bug entry using the image g...
CVE-2018-12384When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-ze...
CVE-2018-18276XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the ad...
CVE-2018-15584Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboar...
CVE-2018-15582Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gn...
CVE-2018-15581Cross-Site Scripting (XSS) vulnerability in adm/faqmasterformupdate.php in gnuboard5 before 5.3.1.6 allows remote attack...
CVE-2018-15580Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attacker...
CVE-2018-5124Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox bef...
CVE-2018-18513A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be...
CVE-2018-18512A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound...
CVE-2018-18511Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImage...
CVE-2018-18510The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the lo...
CVE-2018-18509A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digit...
CVE-2018-5179A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to m...
CVE-2018-19359GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access C...
CVE-2018-18643GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
CVE-2018-18824WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18823WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18367Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible...
CVE-2018-18366Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 R...
CVE-2018-18285SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now