2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14851exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2...
CVE-2018-1155MEDIUM5.4In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to i...
CVE-2018-1154HIGH8.8In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to autom...
CVE-2018-10922HIGH7.5An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of se...
CVE-2018-10921MEDIUM4.3Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le...
CVE-2018-7649Monitorix before 3.10.1 allows XSS via CGI variables.
CVE-2018-8037If an async request was completed by the application at the same time as the container triggered the async timeout, a ra...
CVE-2018-1554MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-1336HIGH7.5An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the d...
CVE-2018-8032MEDIUM6.1Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/serv...
CVE-2018-1329Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-12448Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar wh...
CVE-2018-10920MEDIUM6.8Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison c...
CVE-2018-3109Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder...
CVE-2018-3108Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification S...
CVE-2018-2933Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S...
CVE-2018-14847CRITICAL9.1MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated ...
CVE-2018-14840uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam...
CVE-2018-14838rejucms 2.1 has stored XSS via the admin/book.php content parameter.
CVE-2018-14836Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able...
CVE-2018-14835Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed i...
CVE-2018-10624In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit...
CVE-2018-3939HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1....
CVE-2018-3924HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version...
CVE-2018-3881CRITICAL9.4An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticate...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now