2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-0557Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary ...
CVE-2018-0529Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2018-0528Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are no...
CVE-2018-0527Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to inject arbitrary web scr...
CVE-2018-0526Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified ...
CVE-2018-12889An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl...
CVE-2018-12884In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create ...
CVE-2018-12882exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_...
CVE-2018-12603Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen...
CVE-2018-11589Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU par...
CVE-2018-11588Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the usernam...
CVE-2018-11587There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric f...
CVE-2018-12735SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inve...
CVE-2018-8755NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downl...
CVE-2018-12602A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
CVE-2018-11046Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks securit...
CVE-2018-11041Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later ...
CVE-2018-10956IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
CVE-2018-1000555Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10188. Reason: This candidate is a reservation...
CVE-2018-1000545Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11416. Reason: This candidate is a reservation...
CVE-2018-1000541Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10362. Reason: This candidate is a reservation...
CVE-2018-1000530Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11522. Reason: This candidate is a reservation...
CVE-2018-1000522Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10364. Reason: This candidate is a reservation...
CVE-2018-12084The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no pe...
CVE-2018-12083The mintToken function of a smart contract implementation for GOAL Bonanza (GOAL), a tradable Ethereum ERC20 token, has ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now