2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1000062WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAct...
CVE-2018-1000061Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-1000060Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 ...
CVE-2018-1000059ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can r...
CVE-2018-1000058Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox pro...
CVE-2018-1000057Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. ...
CVE-2018-1000056Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, a...
CVE-2018-1000055Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build proc...
CVE-2018-1000054Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allo...
CVE-2018-1000053LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation ...
CVE-2018-1000051Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Po...
CVE-2018-1000050Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. ...
CVE-2018-1000049Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner...
CVE-2018-1000048NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval f...
CVE-2018-1000047NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result i...
CVE-2018-1000046NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remot...
CVE-2018-1000045NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in...
CVE-2018-1000044Security Onion Solutions Squert version 1.1.1 through 1.6.7 contains a SQL Injection vulnerability in .inc/callback.php ...
CVE-2018-1000043Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elemen...
CVE-2018-1000042Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elemen...
CVE-2018-1000041GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulner...
CVE-2018-1000035A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives t...
CVE-2018-1000034An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service an...
CVE-2018-1000033An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service an...
CVE-2018-1000032A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of ser...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now