2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-12529An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabil...
CVE-2018-12528An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for ...
CVE-2018-12499The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM)...
CVE-2018-10076An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remo...
CVE-2018-10075Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject ...
CVE-2018-13056An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its ...
CVE-2018-13054An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows conf...
CVE-2018-8039It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol....
CVE-2018-13053The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow v...
CVE-2018-0499A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists ...
CVE-2018-13050A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_usernam...
CVE-2018-13049The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by t...
CVE-2018-13043scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YA...
CVE-2018-13040OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.p...
CVE-2018-13039OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI.
CVE-2018-13038OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. Thi...
CVE-2018-13037An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a ...
CVE-2018-13033The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to c...
CVE-2018-13032ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi...
CVE-2018-12990phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
CVE-2018-13030An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cau...
CVE-2018-13026An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP...
CVE-2018-13025protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via...
CVE-2018-13024Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter t...
CVE-2018-13021An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code exe...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now