2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-14941Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for th...
CVE-2018-14940PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and wi...
CVE-2018-14939The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in...
CVE-2018-14938An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the fun...
CVE-2018-14937The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
CVE-2018-14936The Add page option in my little forum 2.4.12 allows XSS via the Title field.
CVE-2018-14593An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x throug...
CVE-2018-14541PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, Sta...
CVE-2018-14497Tenda D152 ADSL routers allow XSS via a crafted SSID.
CVE-2018-14473OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be e...
CVE-2018-14417A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul...
CVE-2018-12483OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the co...
CVE-2018-12482OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit ...
CVE-2018-14929Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home ...
CVE-2018-14928/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file para...
CVE-2018-14927Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application fold...
CVE-2018-14926Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
CVE-2018-14925Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegi...
CVE-2018-14924Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nom...
CVE-2018-14923A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via vid...
CVE-2018-5490Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and ther...
CVE-2018-14912cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned...
CVE-2018-14911A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filt...
CVE-2018-14910SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (...
CVE-2018-7748report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now