2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14593An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x throug...
CVE-2018-14541PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, Sta...
CVE-2018-14497Tenda D152 ADSL routers allow XSS via a crafted SSID.
CVE-2018-14473OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be e...
CVE-2018-14417A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul...
CVE-2018-12483OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the co...
CVE-2018-12482OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit ...
CVE-2018-14929Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home ...
CVE-2018-14928/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file para...
CVE-2018-14927Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application fold...
CVE-2018-14926Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
CVE-2018-14925Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegi...
CVE-2018-14924Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nom...
CVE-2018-9866CRITICAL9.8A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management S...
CVE-2018-3777CRITICAL9.8Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API r...
CVE-2018-14923A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via vid...
CVE-2018-5490Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and ther...
CVE-2018-14912cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned...
CVE-2018-14911A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filt...
CVE-2018-14910SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (...
CVE-2018-7748report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via...
CVE-2018-14908Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printin...
CVE-2018-14907The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in St...
CVE-2018-14906The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.
CVE-2018-14905The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now