2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16179 | — | — | 0.5% | Jan 9, 2019 | The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-th... |
| CVE-2018-16178 | — | — | 1.4% | Jan 9, 2019 | Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only fo... |
| CVE-2018-16177 | HIGH | 7.8 | 0.4% | Jan 9, 2019 | Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measu... |
| CVE-2018-16176 | — | — | 1.0% | Jan 9, 2019 | Untrusted search path vulnerability in Installer of Mapping Tool 2.0.1.6 and 2.0.1.7 allows remote attackers to gain pri... |
| CVE-2018-16175 | — | — | 1.3% | Jan 9, 2019 | SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execut... |
| CVE-2018-16174 | — | — | 1.0% | Jan 9, 2019 | Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary ... |
| CVE-2018-16173 | — | — | 1.0% | Jan 9, 2019 | Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web ... |
| CVE-2018-16172 | — | — | 0.6% | Jan 9, 2019 | Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Re... |
| CVE-2018-16171 | — | — | 1.9% | Jan 9, 2019 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code f... |
| CVE-2018-16170 | — | — | 1.7% | Jan 9, 2019 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attack... |
| CVE-2018-16169 | — | — | 1.3% | Jan 9, 2019 | Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the s... |
| CVE-2018-16168 | — | — | 2.4% | Jan 9, 2019 | LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors. |
| CVE-2018-16167 | — | — | 74.7% | Jan 9, 2019 | LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-16166 | — | — | 1.9% | Jan 9, 2019 | LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vecto... |
| CVE-2018-16165 | — | — | 1.1% | Jan 9, 2019 | Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web scri... |
| CVE-2018-16164 | — | — | 1.2% | Jan 9, 2019 | Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers... |
| CVE-2018-1000426 | MEDIUM | 6.1 | 1.0% | Jan 9, 2019 | A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecora... |
| CVE-2018-1000425 | — | — | 0.3% | Jan 9, 2019 | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in Sona... |
| CVE-2018-1000424 | — | — | 0.3% | Jan 9, 2019 | An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in Artifac... |
| CVE-2018-1000423 | — | — | 0.3% | Jan 9, 2019 | An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in ... |
| CVE-2018-1000422 | — | — | 0.8% | Jan 9, 2019 | An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityR... |
| CVE-2018-1000421 | — | — | 1.3% | Jan 9, 2019 | An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows... |
| CVE-2018-1000420 | — | — | 1.4% | Jan 9, 2019 | An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows... |
| CVE-2018-1000419 | — | — | 1.6% | Jan 9, 2019 | An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that ... |
| CVE-2018-1000418 | — | — | 1.1% | Jan 9, 2019 | An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now