2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11537Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers ...
CVE-2018-11526The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
CVE-2018-11525The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
CVE-2018-12583An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
CVE-2018-12582An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&...
CVE-2018-12580library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 a...
CVE-2018-12578There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of ser...
CVE-2018-12564An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can f...
CVE-2018-12563An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-ser...
CVE-2018-12562An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wr...
CVE-2018-12561An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additio...
CVE-2018-12560An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be perform...
CVE-2018-12559An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mo...
CVE-2018-12557An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a ta...
CVE-2018-10623Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buf...
CVE-2018-10621Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer whe...
CVE-2018-10617Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer wher...
CVE-2018-9029An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL in...
CVE-2018-9028Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
CVE-2018-9027A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute ma...
CVE-2018-9026A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions wit...
CVE-2018-9025An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with s...
CVE-2018-9024An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a...
CVE-2018-9023An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary com...
CVE-2018-1333By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker ex...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now