2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9101 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-8716 | — | — | 39.3% | Apr 25, 2018 | WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. |
| CVE-2018-10213 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a di... |
| CVE-2018-10212 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creatio... |
| CVE-2018-10211 | — | — | 1.1% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the h... |
| CVE-2018-10210 | — | — | 1.1% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the passw... |
| CVE-2018-10209 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download... |
| CVE-2018-10208 | — | — | 0.8% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page... |
| CVE-2018-10207 | — | — | 1.1% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on t... |
| CVE-2018-10206 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field... |
| CVE-2018-1363 | — | — | 1.0% | Apr 25, 2018 | IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vul... |
| CVE-2018-8801 | — | — | 1.3% | Apr 25, 2018 | GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and w... |
| CVE-2018-10376 | — | — | 1.8% | Apr 25, 2018 | An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereu... |
| CVE-2018-10375 | — | — | 1.2% | Apr 25, 2018 | A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized b... |
| CVE-2018-10374 | — | — | 0.7% | Apr 25, 2018 | EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request... |
| CVE-2018-10373 | — | — | 3.5% | Apr 25, 2018 | concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.3... |
| CVE-2018-10372 | — | — | 2.4% | Apr 25, 2018 | process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buf... |
| CVE-2018-10368 | — | — | 0.7% | Apr 25, 2018 | An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an ... |
| CVE-2018-10367 | — | — | 0.7% | Apr 25, 2018 | An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content secti... |
| CVE-2018-10366 | — | — | 2.6% | Apr 25, 2018 | An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam... |
| CVE-2018-10310 | — | — | 3.9% | Apr 25, 2018 | A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse... |
| CVE-2018-10362 | — | — | 1.5% | Apr 25, 2018 | An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in cla... |
| CVE-2018-10361 | — | — | 0.4% | Apr 25, 2018 | An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's ... |
| CVE-2018-1059 | — | — | 0.9% | Apr 24, 2018 | The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contigu... |
| CVE-2018-9131 | — | — | — | Apr 24, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now