2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3748There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTM...
CVE-2018-3747The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to...
CVE-2018-8036In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite lo...
CVE-2018-13116/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
CVE-2018-13113HIGH7.5The transfer and transferFrom functions of a smart contract implementation for Easy Trading Token (ETT), an Ethereum tok...
CVE-2018-13112get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buff...
CVE-2018-11643SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authentic...
CVE-2018-11642Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS...
CVE-2018-11641Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Di...
CVE-2018-11640XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attac...
CVE-2018-11639Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrat...
CVE-2018-11638Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5...
CVE-2018-11637Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote att...
CVE-2018-11636Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 all...
CVE-2018-11635Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php ...
CVE-2018-11634Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local user...
CVE-2018-11052CRITICAL9.8Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attac...
CVE-2018-11051HIGH7.5RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA C...
CVE-2018-13106ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
CVE-2018-13102AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.
CVE-2018-11316The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can r...
CVE-2018-11314The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result...
CVE-2018-7635Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar wh...
CVE-2018-7787In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validati...
CVE-2018-7786In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now