2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0499A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists ...
CVE-2018-13050A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_usernam...
CVE-2018-13049The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by t...
CVE-2018-13043scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YA...
CVE-2018-13041HIGH7.5The mint function of a smart contract implementation for Link Platform (LNK), an Ethereum ERC20 token, has an integer ov...
CVE-2018-13040OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.p...
CVE-2018-13039OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI.
CVE-2018-13038OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. Thi...
CVE-2018-13037An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a ...
CVE-2018-13033The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to c...
CVE-2018-13032ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi...
CVE-2018-7475MEDIUM6.1Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers t...
CVE-2018-12990phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
CVE-2018-13030An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cau...
CVE-2018-13026An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP...
CVE-2018-10860MEDIUM5.4perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did n...
CVE-2018-13025protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via...
CVE-2018-13024Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter t...
CVE-2018-13021An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code exe...
CVE-2018-12465CRITICAL9.1An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) ...
CVE-2018-12464CRITICAL10A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gatewa...
CVE-2018-8902An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single sh...
CVE-2018-8901An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access priv...
CVE-2018-13014Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, ...
CVE-2018-13013Improper check of unusual conditions when launching msiexec.exe in safensec.com (SysWatch service) in SAFE'N'SEC SoftCon...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now