2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18371——The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:...
CVE-2018-18370——The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:...
CVE-2018-15513——Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a ...
CVE-2018-15512——Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows rem...
CVE-2018-15511——Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows rem...
CVE-2018-15510——Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attack...
CVE-2018-21007——The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders i...
CVE-2018-21006——The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
CVE-2018-21005——The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
CVE-2018-21004——The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
CVE-2018-21003——The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2018-21002——The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2018-21001——The anycomment plugin before 0.0.33 for WordPress has XSS.
CVE-2018-17557——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-20986. Reason: This candidate is a reservation d...
CVE-2018-18668——GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t...
CVE-2018-20998——An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mis...
CVE-2018-20997——An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
CVE-2018-20996——An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor misha...
CVE-2018-20995——An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption be...
CVE-2018-20989——An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow an...
CVE-2018-21000——An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong o...
CVE-2018-20999——An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
CVE-2018-20991——An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors,...
CVE-2018-20994——An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because ...
CVE-2018-20993——An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserializa...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now