2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6345CRITICAL9.8The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively ...
CVE-2018-14662MEDIUM5.7It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e...
CVE-2018-15463MEDIUM6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-1772IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-15440MEDIUM6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-16846MEDIUM6.5It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAP...
CVE-2018-20719In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history p...
CVE-2018-20718In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:...
CVE-2018-20717In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a ...
CVE-2018-20716CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
CVE-2018-20715The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the...
CVE-2018-20714The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vuln...
CVE-2018-20713Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
CVE-2018-20712A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in...
CVE-2018-16888MEDIUM4.7It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When ...
CVE-2018-16886HIGH8.1etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-b...
CVE-2018-1969CRITICAL9IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be autom...
CVE-2018-1967MEDIUM6.1IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2018-1956MEDIUM5.9IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it ...
CVE-2018-20703CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
CVE-2018-16887MEDIUM5.4A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/...
CVE-2018-16206Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject a...
CVE-2018-20699Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large intege...
CVE-2018-16865HIGH7.8An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover...
CVE-2018-16864HIGH7.8An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now