2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16749MEDIUM6.5In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause...
CVE-2018-16736In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec...
CVE-2018-16733In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the...
CVE-2018-16732\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
CVE-2018-16731CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg,...
CVE-2018-16730\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.
CVE-2018-16725An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id paramet...
CVE-2018-16724An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index req...
CVE-2018-16715An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %Pro...
CVE-2018-9283An XSS issue was discovered in CremeCRM 1.6.12. It is affected by 10 stored Cross-Site Scripting (XSS) vulnerabilities i...
CVE-2018-16454PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface cha...
CVE-2018-16363The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_f...
CVE-2018-16059Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par...
CVE-2018-15552HIGH7.5The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling...
CVE-2018-15486An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and Fi...
CVE-2018-15485An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or auth...
CVE-2018-15484An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is po...
CVE-2018-15483An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Denial of Service can occur through the ope...
CVE-2018-15474CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04...
CVE-2018-14398An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header,...
CVE-2018-14397An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting...
CVE-2018-14396An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vu...
CVE-2018-12897SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
CVE-2018-16710OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP re...
CVE-2018-16709Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now