2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18803Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb...
CVE-2018-18801The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=...
CVE-2018-18799School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
CVE-2018-18797School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
CVE-2018-18796Library Management System 1.0 has SQL Injection via the "Search for Books" screen.
CVE-2018-18795School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
CVE-2018-18794School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
CVE-2018-18793School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
CVE-2018-18763SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
CVE-2018-18760RhinOS 3.0 build 1190 allows CSRF.
CVE-2018-18759Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
CVE-2018-18756Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008.
CVE-2018-16396An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. I...
CVE-2018-16395An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x b...
CVE-2018-15693Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure di...
CVE-2018-15692Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipu...
CVE-2018-9086In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download comman...
CVE-2018-9085A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potenti...
CVE-2018-9073Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain sec...
CVE-2018-9071Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information relat...
CVE-2018-19301tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later v...
CVE-2018-18954The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV...
CVE-2018-16620Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
CVE-2018-16619Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-14935The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now