2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18980An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpMan...
CVE-2018-18966osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in ca...
CVE-2018-18965osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in ca...
CVE-2018-18964osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in ca...
CVE-2018-17913A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, w...
CVE-2018-17909When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is...
CVE-2018-17907When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offse...
CVE-2018-17905When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memo...
CVE-2018-18957An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu...
CVE-2018-13397There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Gi...
CVE-2018-13396There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git su...
CVE-2018-18956The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a den...
CVE-2018-18820A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enable...
CVE-2018-9208Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta
CVE-2018-18952JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
CVE-2018-18950KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directo...
CVE-2018-18949Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
CVE-2018-18943An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category ...
CVE-2018-18942In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the ...
CVE-2018-18939An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
CVE-2018-18938An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to...
CVE-2018-18937An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_c...
CVE-2018-18936An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via dir...
CVE-2018-18935An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as dem...
CVE-2018-18934An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now