2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16490A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary propert...
CVE-2018-16489CRITICAL9.8A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object....
CVE-2018-16487MEDIUM5.6A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep ...
CVE-2018-16486A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject prope...
CVE-2018-16485Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file ...
CVE-2018-16484A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, du...
CVE-2018-16483A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the appl...
CVE-2018-16482HIGH7.5A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to acce...
CVE-2018-16481A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's br...
CVE-2018-16480A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due t...
CVE-2018-16479Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appe...
CVE-2018-0722Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, ...
CVE-2018-18988LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report form...
CVE-2018-5498Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attac...
CVE-2018-15617MEDIUM6.5A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remo...
CVE-2018-15779Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2018-5560CRITICAL10A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla ...
CVE-2018-17928The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration f...
CVE-2018-6241NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the regi...
CVE-2018-12548In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public ...
CVE-2018-19043The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)...
CVE-2018-19042The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di...
CVE-2018-19041The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the...
CVE-2018-19040The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para...
CVE-2018-18941In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discoverin...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now