2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1551LOW3.1IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they ...
CVE-2018-1528MEDIUM4.3IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the...
CVE-2018-1422MEDIUM5.4IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable...
CVE-2018-14959An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI.
CVE-2018-14958An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and descrip...
CVE-2018-14955The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
CVE-2018-14954The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
CVE-2018-14953The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
CVE-2018-14952The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
CVE-2018-14951The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
CVE-2018-14950The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
CVE-2018-14948An issue has been found in dilawar sound through 2017-11-27. The end of openWavFile in wav-file.cc has Mismatched Memory...
CVE-2018-14947An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines ...
CVE-2018-14946An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routi...
CVE-2018-14945An issue has been found in jpeg_encoder through 2015-11-27. It is a heap-based buffer overflow in the function readFromB...
CVE-2018-14944An issue has been found in jpeg_encoder through 2015-11-27. It is a SEGV in the function readFromBMP in jpeg_encoder.cpp...
CVE-2018-14943Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for ...
CVE-2018-14942Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "P...
CVE-2018-14941Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for th...
CVE-2018-14940PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and wi...
CVE-2018-14939The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in...
CVE-2018-14938An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the fun...
CVE-2018-14937The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
CVE-2018-14936The Add page option in my little forum 2.4.12 allows XSS via the Title field.
CVE-2018-14933CRITICAL9.8upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now