2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1771HIGH8.4IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in th...
CVE-2018-1677MEDIUM5.1IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of serv...
CVE-2018-1661MEDIUM6.5IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2018-8653HIGH7.5A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2018-6669MEDIUM6.3A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or loca...
CVE-2018-20307MEDIUM4.3Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain ...
CVE-2018-20306A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traff...
CVE-2018-20301An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In pa...
CVE-2018-20305D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass paramete...
CVE-2018-20304wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via...
CVE-2018-20303In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an att...
CVE-2018-20302An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.
CVE-2018-20300Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm ...
CVE-2018-20299CRITICAL9.8An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firm...
CVE-2018-15801HIGH7.4Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation...
CVE-2018-15798HIGH7.6Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unau...
CVE-2018-11799Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can...
CVE-2018-19598Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
CVE-2018-19597CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
CVE-2018-19596Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.
CVE-2018-19508CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.
CVE-2018-19507CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.
CVE-2018-19506Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/defau...
CVE-2018-18999HIGH7.3WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user suppl...
CVE-2018-20298S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now