2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-15199AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
CVE-2018-15198An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a use...
CVE-2018-15197An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that...
CVE-2018-15193A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via ...
CVE-2018-15192An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access ...
CVE-2018-15178Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and cond...
CVE-2018-15177In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
CVE-2018-15176XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x00000...
CVE-2018-15175XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVar...
CVE-2018-15174XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and a...
CVE-2018-15173Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption ...
CVE-2018-15169A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 all...
CVE-2018-15168A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids ...
CVE-2018-15137CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)...
CVE-2018-5995The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sens...
CVE-2018-15132An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and...
CVE-2018-12885The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random valu...
CVE-2018-11456A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network a...
CVE-2018-11455A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager...
CVE-2018-11454A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), ...
CVE-2018-11453A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), ...
CVE-2018-15130ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
CVE-2018-15129ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
CVE-2018-14869PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field i...
CVE-2018-14857Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventor...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now