2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16732\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
CVE-2018-16731CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg,...
CVE-2018-16730\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.
CVE-2018-16725An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id paramet...
CVE-2018-16724An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index req...
CVE-2018-16715An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %Pro...
CVE-2018-9283An XSS issue was discovered in CremeCRM 1.6.12. It is affected by 10 stored Cross-Site Scripting (XSS) vulnerabilities i...
CVE-2018-16454PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface cha...
CVE-2018-16363The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_f...
CVE-2018-16059Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par...
CVE-2018-15486An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and Fi...
CVE-2018-15485An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or auth...
CVE-2018-15484An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is po...
CVE-2018-15483An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Denial of Service can occur through the ope...
CVE-2018-15474CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04...
CVE-2018-14398An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header,...
CVE-2018-14397An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting...
CVE-2018-14396An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vu...
CVE-2018-12897SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
CVE-2018-16710OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP re...
CVE-2018-16709Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V...
CVE-2018-16460A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker co...
CVE-2018-16704An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possibl...
CVE-2018-16703A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple us...
CVE-2018-16667An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c wh...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now