2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-19796An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via ...
CVE-2018-19795ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full a...
CVE-2018-19794Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to...
CVE-2018-19793jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 ...
CVE-2018-19792The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow)...
CVE-2018-19791The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing a...
CVE-2018-19788A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully exec...
CVE-2018-19785PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.
CVE-2018-19784The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, whic...
CVE-2018-15716NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques...
CVE-2018-15715Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0...
CVE-2018-7831An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded we...
CVE-2018-7830Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedd...
CVE-2018-7811An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC...
CVE-2018-7810An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embe...
CVE-2018-7809An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC...
CVE-2018-7807Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the serve...
CVE-2018-7806Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, ma...
CVE-2018-16477A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify...
CVE-2018-16476A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can c...
CVE-2018-19290In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command...
CVE-2018-18987VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without...
CVE-2018-18983VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) in...
CVE-2018-18860A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-...
CVE-2018-15835Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now