2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18247Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
CVE-2018-18246Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module...
CVE-2018-18245Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered...
CVE-2018-20173Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVE-2018-20170OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster respon...
CVE-2018-20169MEDIUM6.8An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading o...
CVE-2018-20168Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which al...
CVE-2018-20167Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat ...
CVE-2018-20161A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable camera...
CVE-2018-20159i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allow...
CVE-2018-20157The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zi...
CVE-2018-20156The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to exec...
CVE-2018-20155The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende...
CVE-2018-20154The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e...
CVE-2018-20153In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privil...
CVE-2018-20152In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted inp...
CVE-2018-20151In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler ...
CVE-2018-20150In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
CVE-2018-20149In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files ...
CVE-2018-20148In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted meta...
CVE-2018-20147In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deletin...
CVE-2018-19007In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration pa...
CVE-2018-1977MEDIUM5.3IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A rem...
CVE-2018-1848MEDIUM6.1IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2018-19413A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive i...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now