2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1000673Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000773. Reason: This candidate is a reservati...
CVE-2018-16551LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
CVE-2018-16550TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by sk...
CVE-2018-16549HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
CVE-2018-16548An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_d...
CVE-2018-16381e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
CVE-2018-16361An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
CVE-2018-16307An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible ...
CVE-2018-16252FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
CVE-2018-16148The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerabl...
CVE-2018-16147The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulner...
CVE-2018-16146The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated a...
CVE-2018-16145The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before ...
CVE-2018-16144The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vuln...
CVE-2018-15918An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission...
CVE-2018-15917Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT...
CVE-2018-15684An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictab...
CVE-2018-15683An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect d...
CVE-2018-15682An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to auto...
CVE-2018-15681An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable...
CVE-2018-15680An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsal...
CVE-2018-15679An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?...
CVE-2018-15678An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=sig...
CVE-2018-15677The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is ...
CVE-2018-15676An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_pr...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now