2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16635Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
CVE-2018-15805Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an att...
CVE-2018-15800HIGH8.1Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicio...
CVE-2018-1279HIGH8.5Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines wh...
CVE-2018-3988MEDIUM4.7Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses th...
CVE-2018-1957MEDIUM4IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by th...
CVE-2018-1671IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML...
CVE-2018-1000866A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/ko...
CVE-2018-1000865A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/koh...
CVE-2018-1000864A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allo...
CVE-2018-1000863A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy....
CVE-2018-1000862An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSu...
CVE-2018-1000861CRITICAL9.8A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea...
CVE-2018-20018S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
CVE-2018-20017SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
CVE-2018-20015YzmCMS v5.2 has admin/role/add.html CSRF.
CVE-2018-20012PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI.
CVE-2018-20011DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
CVE-2018-20010DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
CVE-2018-20009DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
CVE-2018-20006An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post...
CVE-2018-20005An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonst...
CVE-2018-20004HIGH8.8An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file...
CVE-2018-20002The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distri...
CVE-2018-20001In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits)...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now