2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-17050The mintToken function of a smart contract implementation for PolyAi (AI), an Ethereum token, has an integer overflow th...
CVE-2018-17003In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title paramete...
CVE-2018-17002On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a...
CVE-2018-17001On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding...
CVE-2018-16965In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceCo...
CVE-2018-16833Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBRE...
CVE-2018-16822SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CVE-2018-16821SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.
CVE-2018-15613HIGH8.3A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could re...
CVE-2018-15612HIGH8.3A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add...
CVE-2018-14732An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's cod...
CVE-2018-14731An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because t...
CVE-2018-14730HIGH7.5An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests i...
CVE-2018-13111There exists a partial Denial of Service vulnerability in Wanscam HW0021 IP Cameras. An attacker could craft a malicious...
CVE-2018-12511In the mintToken function of a smart contract implementation for Substratum (SUB), an Ethereum ERC20 token, the administ...
CVE-2018-9282An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vu...
CVE-2018-16793Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parame...
CVE-2018-16597An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by l...
CVE-2018-16281The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control.
CVE-2018-14691An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulne...
CVE-2018-14690An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerab...
CVE-2018-14689An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vul...
CVE-2018-14688An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerab...
CVE-2018-11352The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored withi...
CVE-2018-3915HIGH8.2An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now