2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14582 | — | — | 0.5% | Jul 24, 2018 | index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. |
| CVE-2018-5387 | HIGH | 7.5 | 1.7% | Jul 24, 2018 | Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that ... |
| CVE-2018-5386 | — | — | 4.6% | Jul 24, 2018 | Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading t... |
| CVE-2018-5385 | — | — | 4.2% | Jul 24, 2018 | Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can l... |
| CVE-2018-5384 | — | — | 4.4% | Jul 24, 2018 | Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection... |
| CVE-2018-14579 | — | — | 1.6% | Jul 24, 2018 | GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to ... |
| CVE-2018-14335 | MEDIUM | 6.5 | 13.4% | Jul 24, 2018 | An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read ... |
| CVE-2018-13386 | — | — | 1.6% | Jul 24, 2018 | There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An atta... |
| CVE-2018-13385 | — | — | 2.2% | Jul 24, 2018 | There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attack... |
| CVE-2018-10905 | HIGH | 7.8 | 0.5% | Jul 24, 2018 | CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. ... |
| CVE-2018-10608 | — | — | 7.8% | Jul 24, 2018 | SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects... |
| CVE-2018-10604 | HIGH | 8.8 | 1.6% | Jul 24, 2018 | SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modific... |
| CVE-2018-10600 | — | — | 2.5% | Jul 24, 2018 | SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may ... |
| CVE-2018-14573 | — | — | 6.4% | Jul 23, 2018 | A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage b... |
| CVE-2018-8031 | — | — | 2.0% | Jul 23, 2018 | The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user ... |
| CVE-2018-10912 | MEDIUM | 4.9 | 1.3% | Jul 23, 2018 | keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with mul... |
| CVE-2018-11452 | — | — | 2.4% | Jul 23, 2018 | A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firm... |
| CVE-2018-11451 | — | — | 2.4% | Jul 23, 2018 | A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firm... |
| CVE-2018-14570 | — | — | 1.8% | Jul 23, 2018 | A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.1... |
| CVE-2018-14568 | — | — | 2.0% | Jul 23, 2018 | Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. This allows detection bypass because Win... |
| CVE-2018-14328 | — | — | 10.7% | Jul 23, 2018 | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti... |
| CVE-2018-1999007 | MEDIUM | 5.4 | 0.9% | Jul 23, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewo... |
| CVE-2018-1999006 | — | — | 0.9% | Jul 23, 2018 | A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.jav... |
| CVE-2018-1999005 | MEDIUM | 5.4 | 0.9% | Jul 23, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.jav... |
| CVE-2018-1999004 | MEDIUM | 4.3 | 0.9% | Jul 23, 2018 | A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java th... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now