2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1002006These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact...
CVE-2018-1002005These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4...
CVE-2018-1002004There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re...
CVE-2018-1002003There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re...
CVE-2018-1002002There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re...
CVE-2018-1002001There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re...
CVE-2018-1002000There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad...
CVE-2018-7116HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via...
CVE-2018-7115HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in db...
CVE-2018-7114HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbma...
CVE-2018-7113A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the ...
CVE-2018-7112The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of pri...
CVE-2018-1840MEDIUM6IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, ca...
CVE-2018-6332MEDIUM5.9A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spe...
CVE-2018-16869MEDIUM5.7A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of ...
CVE-2018-16868MEDIUM5.6A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA d...
CVE-2018-16855HIGH7.5An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigge...
CVE-2018-19797In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (use...
CVE-2018-19796An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via ...
CVE-2018-19795ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full a...
CVE-2018-19794Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to...
CVE-2018-19793jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 ...
CVE-2018-19792The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow)...
CVE-2018-19791The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing a...
CVE-2018-19788A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully exec...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now