2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-19766Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "GroupRessourceAdmin.jsp" ha...
CVE-2018-19765Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp...
CVE-2018-19649XSS exists in InfoVista VistaPortal SE Version 5.1 (build 51029). VPortal/mgtconsole/RolePermissions.jsp has reflected X...
CVE-2018-19295Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
CVE-2018-18250Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as...
CVE-2018-18249Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the...
CVE-2018-18248Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string,...
CVE-2018-18247Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
CVE-2018-18246Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module...
CVE-2018-18245Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered...
CVE-2018-20173Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVE-2018-20170OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster respon...
CVE-2018-20168Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which al...
CVE-2018-20167Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat ...
CVE-2018-20161A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable camera...
CVE-2018-20159i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allow...
CVE-2018-20157The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zi...
CVE-2018-20156The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to exec...
CVE-2018-20155The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende...
CVE-2018-20154The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e...
CVE-2018-20153In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privil...
CVE-2018-20152In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted inp...
CVE-2018-20151In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler ...
CVE-2018-20150In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
CVE-2018-20149In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now