2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-6294Unsecured way of firmware update in Hanwha Techwin Smartcams
CVE-2018-1000093CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as...
CVE-2018-1000092CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page t...
CVE-2018-1000091KadNode version version 2.2.0 contains a Buffer Overflow vulnerability in Arguments when starting up the binary that can...
CVE-2018-1000090textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial...
CVE-2018-1000089Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATIO...
CVE-2018-1000088Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form,...
CVE-2018-1000087WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create...
CVE-2018-1000086NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in ...
CVE-2018-1000085ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_c...
CVE-2018-1000084WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout...
CVE-2018-1000083Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The r...
CVE-2018-1000082Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the...
CVE-2018-1000081Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can resu...
CVE-2018-1000080Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The downlo...
CVE-2018-1000079RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000078RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000077RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000076RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000075RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000074RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000073RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl...
CVE-2018-1000072iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can res...
CVE-2018-1000071roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in e...
CVE-2018-1000070Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) cont...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now