2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13884——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2018-20969——do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the ...
CVE-2018-14062——The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of servi...
CVE-2018-14672——In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files ...
CVE-2018-14671——In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remo...
CVE-2018-14670——Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
CVE-2018-14669——ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a mali...
CVE-2018-14668——In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat...
CVE-2018-14008——Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
CVE-2018-12357——Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
CVE-2018-12101——CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields...
CVE-2018-19386——SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, ...
CVE-2018-20968——The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
CVE-2018-20967——The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
CVE-2018-20964——The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20963——The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2018-20966——The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-20827——The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript ...
CVE-2018-20858——Recommender before 2018-07-18 allows XSS.
CVE-2018-20960——Nespresso Prodigio devices lack Bluetooth connection security.
CVE-2018-20957——The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
CVE-2018-20956——Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by...
CVE-2018-20955——Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers ...
CVE-2018-20954——The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expire...
CVE-2018-20962——The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now