2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1000664daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnera...
CVE-2018-1000663jsish version 2.4.70 2.047 contains a Buffer Overflow vulnerability in function _jsi_evalcode from jsiEval.c that can re...
CVE-2018-1000661jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can ...
CVE-2018-1000660TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b...
CVE-2018-1000659LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulne...
CVE-2018-1000658LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an at...
CVE-2018-16606In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted paper...
CVE-2018-16604An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary P...
CVE-2018-1000773WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can re...
CVE-2018-1695HIGH7.3IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to con...
CVE-2018-16585An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even th...
CVE-2018-14632HIGH7.7An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Contai...
CVE-2018-14624HIGH7.5A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the ...
CVE-2018-11263In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is ...
CVE-2018-16459An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
CVE-2018-1000673Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000773. Reason: This candidate is a reservati...
CVE-2018-16552HIGH8.8MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.
CVE-2018-16551LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
CVE-2018-16550TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by sk...
CVE-2018-16549HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
CVE-2018-16548An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_d...
CVE-2018-16381e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
CVE-2018-16361An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
CVE-2018-16307An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible ...
CVE-2018-16252FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now