2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20239MEDIUM5.4Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version...
CVE-2018-2007MEDIUM5.9IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to...
CVE-2018-2004MEDIUM5.4IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2018-1961MEDIUM5.3IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from...
CVE-2018-5123——A third party website can access information available to a user with access to a restricted bug entry using the image g...
CVE-2018-12384——When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-ze...
CVE-2018-18276——XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the ad...
CVE-2018-15584——Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboar...
CVE-2018-15582——Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gn...
CVE-2018-15581——Cross-Site Scripting (XSS) vulnerability in adm/faqmasterformupdate.php in gnuboard5 before 5.3.1.6 allows remote attack...
CVE-2018-15580——Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attacker...
CVE-2018-5124——Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox bef...
CVE-2018-18513——A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be...
CVE-2018-18512——A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound...
CVE-2018-18511——Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImage...
CVE-2018-18510——The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the lo...
CVE-2018-18509——A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digit...
CVE-2018-5179——A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to m...
CVE-2018-19359——GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access C...
CVE-2018-18643——GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
CVE-2018-18824——WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18823——WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18367——Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible...
CVE-2018-18366——Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 R...
CVE-2018-18285——SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now