2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13398 | — | — | 0.5% | Sep 18, 2018 | The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers... |
| CVE-2018-11787 | — | — | 2.6% | Sep 18, 2018 | In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available... |
| CVE-2018-11786 | — | — | 1.9% | Sep 18, 2018 | In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the runni... |
| CVE-2018-7991 | — | — | 0.2% | Sep 18, 2018 | Huawei smartphones Mate10 with versions earlier before ALP-AL00B 8.0.0.110(C00) have a Factory Reset Protection (FRP) by... |
| CVE-2018-7929 | — | — | 0.2% | Sep 18, 2018 | Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. A... |
| CVE-2018-16959 | — | — | 1.2% | Sep 18, 2018 | An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecur... |
| CVE-2018-16958 | — | — | 0.9% | Sep 18, 2018 | An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, whe... |
| CVE-2018-16957 | — | — | 3.4% | Sep 18, 2018 | The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded passwor... |
| CVE-2018-16956 | — | — | 1.2% | Sep 18, 2018 | The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when proces... |
| CVE-2018-16955 | — | — | 0.8% | Sep 18, 2018 | The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). ... |
| CVE-2018-16954 | — | — | 1.1% | Sep 18, 2018 | An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to... |
| CVE-2018-16953 | — | — | 0.8% | Sep 18, 2018 | The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 i... |
| CVE-2018-16952 | — | — | 0.7% | Sep 18, 2018 | The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its d... |
| CVE-2018-14320 | — | — | 2.4% | Sep 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User... |
| CVE-2018-1198 | — | — | 1.0% | Sep 17, 2018 | Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A m... |
| CVE-2018-11088 | — | — | 1.0% | Sep 17, 2018 | Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.... |
| CVE-2018-11086 | — | — | 1.0% | Sep 17, 2018 | Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior... |
| CVE-2018-8041 | — | — | 9.8% | Sep 17, 2018 | Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal. |
| CVE-2018-11781 | — | — | 1.0% | Sep 17, 2018 | Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. |
| CVE-2018-11780 | — | — | 10.8% | Sep 17, 2018 | A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. |
| CVE-2018-17140 | — | — | 0.7% | Sep 17, 2018 | The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp... |
| CVE-2018-17139 | — | — | 3.1% | Sep 17, 2018 | UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /product... |
| CVE-2018-17138 | — | — | 0.7% | Sep 17, 2018 | The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php... |
| CVE-2018-17137 | — | — | 1.4% | Sep 17, 2018 | Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, wh... |
| CVE-2018-17136 | — | — | 1.2% | Sep 17, 2018 | zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now