2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19994An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated use...
CVE-2018-19993A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web s...
CVE-2018-19992A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrar...
CVE-2018-19862Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re...
CVE-2018-19861Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re...
CVE-2018-19523DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user ...
CVE-2018-19505Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, w...
CVE-2018-19415Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via ...
CVE-2018-19414Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web s...
CVE-2018-14481Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.
CVE-2018-17161In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validat...
CVE-2018-16885MEDIUM4.7A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with ...
CVE-2018-16882HIGH8.8A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1...
CVE-2018-16870It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade...
CVE-2018-16876MEDIUM5.3ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on...
CVE-2018-16879CRITICAL9.8Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration chann...
CVE-2018-20662MEDIUM6.5In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by...
CVE-2018-17172The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 ...
CVE-2018-20131The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on t...
CVE-2018-18893Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.jav...
CVE-2018-18264Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for rea...
CVE-2018-20326ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage...
CVE-2018-20211ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with ...
CVE-2018-20166A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a...
CVE-2018-20114CRITICAL9.8On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now