2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14582index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
CVE-2018-5387HIGH7.5Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that ...
CVE-2018-5386Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading t...
CVE-2018-5385Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can l...
CVE-2018-5384Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection...
CVE-2018-14579GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to ...
CVE-2018-14335MEDIUM6.5An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read ...
CVE-2018-13386There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An atta...
CVE-2018-13385There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attack...
CVE-2018-10905HIGH7.8CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. ...
CVE-2018-10608SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects...
CVE-2018-10604HIGH8.8SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modific...
CVE-2018-10600SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may ...
CVE-2018-14573A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage b...
CVE-2018-8031The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user ...
CVE-2018-10912MEDIUM4.9keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with mul...
CVE-2018-11452A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firm...
CVE-2018-11451A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firm...
CVE-2018-14570A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.1...
CVE-2018-14568Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. This allows detection bypass because Win...
CVE-2018-14328Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti...
CVE-2018-1999007MEDIUM5.4A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewo...
CVE-2018-1999006A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.jav...
CVE-2018-1999005MEDIUM5.4A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.jav...
CVE-2018-1999004MEDIUM4.3A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java th...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now