2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13398The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers...
CVE-2018-11787In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available...
CVE-2018-11786In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the runni...
CVE-2018-7991Huawei smartphones Mate10 with versions earlier before ALP-AL00B 8.0.0.110(C00) have a Factory Reset Protection (FRP) by...
CVE-2018-7929Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. A...
CVE-2018-16959An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecur...
CVE-2018-16958An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, whe...
CVE-2018-16957The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded passwor...
CVE-2018-16956The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when proces...
CVE-2018-16955The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). ...
CVE-2018-16954An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to...
CVE-2018-16953The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 i...
CVE-2018-16952The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its d...
CVE-2018-14320This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User...
CVE-2018-1198Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A m...
CVE-2018-11088Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2....
CVE-2018-11086Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior...
CVE-2018-8041Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
CVE-2018-11781Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
CVE-2018-11780A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
CVE-2018-17140The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp...
CVE-2018-17139UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /product...
CVE-2018-17138The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php...
CVE-2018-17137Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, wh...
CVE-2018-17136zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now