2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-9101A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli...
CVE-2018-8716WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
CVE-2018-10213An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a di...
CVE-2018-10212An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creatio...
CVE-2018-10211An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the h...
CVE-2018-10210An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the passw...
CVE-2018-10209An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download...
CVE-2018-10208An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page...
CVE-2018-10207An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on t...
CVE-2018-10206An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field...
CVE-2018-1363IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vul...
CVE-2018-8801GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and w...
CVE-2018-10376An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereu...
CVE-2018-10375A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized b...
CVE-2018-10374EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request...
CVE-2018-10373concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.3...
CVE-2018-10372process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buf...
CVE-2018-10368An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an ...
CVE-2018-10367An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content secti...
CVE-2018-10366An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam...
CVE-2018-10310A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse...
CVE-2018-10362An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in cla...
CVE-2018-10361An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's ...
CVE-2018-1059The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contigu...
CVE-2018-9131Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now