2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000820 | — | — | 1.9% | Dec 20, 2018 | neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in ... |
| CVE-2018-1000817 | — | — | 2.5% | Dec 20, 2018 | Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Acce... |
| CVE-2018-1000816 | — | — | 0.7% | Dec 20, 2018 | Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphi... |
| CVE-2018-1000815 | — | — | 1.1% | Dec 20, 2018 | Brave Software Inc. Brave version version 0.22.810 to 0.24.0 contains a Other/Unknown vulnerability in function ContentS... |
| CVE-2018-1000813 | — | — | 0.7% | Dec 20, 2018 | Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom cl... |
| CVE-2018-1000812 | — | — | 2.0% | Dec 20, 2018 | Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mech... |
| CVE-2018-1000811 | — | — | 47.6% | Dec 20, 2018 | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages... |
| CVE-2018-20306 | — | — | 0.5% | Dec 20, 2018 | A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traff... |
| CVE-2018-20301 | — | — | 0.9% | Dec 20, 2018 | An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In pa... |
| CVE-2018-20305 | — | — | 4.1% | Dec 20, 2018 | D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass paramete... |
| CVE-2018-20304 | — | — | 0.9% | Dec 20, 2018 | wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via... |
| CVE-2018-20303 | — | — | 3.2% | Dec 20, 2018 | In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an att... |
| CVE-2018-20302 | — | — | 0.9% | Dec 20, 2018 | An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter. |
| CVE-2018-20300 | — | — | 1.6% | Dec 20, 2018 | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm ... |
| CVE-2018-11799 | — | — | 1.5% | Dec 19, 2018 | Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can... |
| CVE-2018-19598 | — | — | 0.6% | Dec 19, 2018 | Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request. |
| CVE-2018-19597 | — | — | 0.7% | Dec 19, 2018 | CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798. |
| CVE-2018-19596 | — | — | 0.6% | Dec 19, 2018 | Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506. |
| CVE-2018-19508 | — | — | 0.6% | Dec 19, 2018 | CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI. |
| CVE-2018-19507 | — | — | 0.6% | Dec 19, 2018 | CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI. |
| CVE-2018-19506 | — | — | 0.6% | Dec 19, 2018 | Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/defau... |
| CVE-2018-20298 | — | — | 1.4% | Dec 19, 2018 | S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary... |
| CVE-2018-6307 | — | — | 26.5% | Dec 19, 2018 | LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code ... |
| CVE-2018-20024 | — | — | 3.3% | Dec 19, 2018 | LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that ... |
| CVE-2018-20023 | — | — | 2.5% | Dec 19, 2018 | LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Re... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now