2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-17002On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a...
CVE-2018-17001On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding...
CVE-2018-16965In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceCo...
CVE-2018-16833Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBRE...
CVE-2018-16822SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CVE-2018-16821SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
CVE-2018-14732An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's cod...
CVE-2018-14731An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because t...
CVE-2018-13111There exists a partial Denial of Service vulnerability in Wanscam HW0021 IP Cameras. An attacker could craft a malicious...
CVE-2018-12511In the mintToken function of a smart contract implementation for Substratum (SUB), an Ethereum ERC20 token, the administ...
CVE-2018-9282An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vu...
CVE-2018-16793Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parame...
CVE-2018-16597An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by l...
CVE-2018-16281The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control.
CVE-2018-14691An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulne...
CVE-2018-14690An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerab...
CVE-2018-14689An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vul...
CVE-2018-14688An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerab...
CVE-2018-11352The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored withi...
CVE-2018-16786DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
CVE-2018-16784DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring...
CVE-2018-11241An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary f...
CVE-2018-11240An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' fea...
CVE-2018-8023Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Ap...
CVE-2018-1685IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now