2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13884Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2018-20969do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the ...
CVE-2018-14062The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of servi...
CVE-2018-14672In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files ...
CVE-2018-14671In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remo...
CVE-2018-14670Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
CVE-2018-14669ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a mali...
CVE-2018-14668In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat...
CVE-2018-14008Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
CVE-2018-12357Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
CVE-2018-12101CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields...
CVE-2018-19386SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, ...
CVE-2018-20968The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
CVE-2018-20967The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
CVE-2018-20964The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20963The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2018-20966The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-20827The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript ...
CVE-2018-20858Recommender before 2018-07-18 allows XSS.
CVE-2018-20960Nespresso Prodigio devices lack Bluetooth connection security.
CVE-2018-20957The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
CVE-2018-20956Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by...
CVE-2018-20955Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers ...
CVE-2018-20954The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expire...
CVE-2018-20962The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now