2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-7265Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS.
CVE-2018-7263The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial...
CVE-2018-5477An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Appli...
CVE-2018-7205Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote a...
CVE-2018-7046Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary op...
CVE-2018-6941A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot...
CVE-2018-6940A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote...
CVE-2018-6459The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote...
CVE-2018-7259The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://insta...
CVE-2018-7254The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of...
CVE-2018-7253The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denia...
CVE-2018-7251An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain...
CVE-2018-5763An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafte...
CVE-2018-6592Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by lev...
CVE-2018-7247An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) c...
CVE-2018-5439A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attack...
CVE-2018-7226An issue was discovered in vcSetXCutTextProc() in VNConsole.c in LinuxVNC and VNCommand from the LibVNC/vncterm distribu...
CVE-2018-7225An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize...
CVE-2018-7219application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or addin...
CVE-2018-6591Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficul...
CVE-2018-1411IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ...
CVE-2018-1410IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ...
CVE-2018-1409IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ...
CVE-2018-6024SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
CVE-2018-7217In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now