2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14904Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as de...
CVE-2018-14728upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
CVE-2018-14715The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game,...
CVE-2018-14576HIGH7.5The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow v...
CVE-2018-14504An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vuln...
CVE-2018-13055A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2....
CVE-2018-12989The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processe...
CVE-2018-12607An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x...
CVE-2018-12606An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x...
CVE-2018-12605An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' ...
CVE-2018-14774An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0...
CVE-2018-14773MEDIUM6.5An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, ...
CVE-2018-14574django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
CVE-2018-13416In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern...
CVE-2018-1524HIGH8.8IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could...
CVE-2018-6590MEDIUM6.1CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerabi...
CVE-2018-5489NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have bee...
CVE-2018-14884An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing...
CVE-2018-14883An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integ...
CVE-2018-14877An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywor...
CVE-2018-14876An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can...
CVE-2018-14873An issue was discovered in Rincewind 0.1. There is a cross-site scripting (XSS) vulnerability involving a p=account requ...
CVE-2018-14872An issue was discovered in Rincewind 0.1. A reinstall vulnerability exists because the parameter p of index.php and anot...
CVE-2018-14858An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_...
CVE-2018-3834HIGH7.4An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmwa...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now