2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16179The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-th...
CVE-2018-16178Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only fo...
CVE-2018-16177HIGH7.8Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measu...
CVE-2018-16176Untrusted search path vulnerability in Installer of Mapping Tool 2.0.1.6 and 2.0.1.7 allows remote attackers to gain pri...
CVE-2018-16175SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execut...
CVE-2018-16174Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary ...
CVE-2018-16173Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web ...
CVE-2018-16172Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Re...
CVE-2018-16171Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code f...
CVE-2018-16170Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attack...
CVE-2018-16169Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the s...
CVE-2018-16168LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
CVE-2018-16167LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2018-16166LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vecto...
CVE-2018-16165Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web scri...
CVE-2018-16164Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers...
CVE-2018-1000426MEDIUM6.1A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecora...
CVE-2018-1000425An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in Sona...
CVE-2018-1000424An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in Artifac...
CVE-2018-1000423An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in ...
CVE-2018-1000422An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityR...
CVE-2018-1000421An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows...
CVE-2018-1000420An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows...
CVE-2018-1000419An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that ...
CVE-2018-1000418An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now