2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5521On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect a...
CVE-2018-5513On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handsh...
CVE-2018-11651Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/...
CVE-2018-11650Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNot...
CVE-2018-11649Hue 3.12 has XSS via the /pig/save/ name and script parameters.
CVE-2018-8922MEDIUM6.5Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access n...
CVE-2018-8921MEDIUM6.5Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote...
CVE-2018-11646webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon...
CVE-2018-11645psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow ...
CVE-2018-9186A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF valida...
CVE-2018-6552Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as...
CVE-2018-1532MEDIUM4.3IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a us...
CVE-2018-1496MEDIUM5.4IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2018-10379An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5...
CVE-2018-11633An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can b...
CVE-2018-11632An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres...
CVE-2018-11631Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notificatio...
CVE-2018-11627Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVE-2018-11626SELA (aka SimplE Lossless Audio) v0.1.2-alpha has a stack-based buffer overflow in the core/apev2.c init_apev2_keys func...
CVE-2018-11142The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management App...
CVE-2018-11141The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE Syste...
CVE-2018-11140The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8...
CVE-2018-11139The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible ...
CVE-2018-11138CRITICAL9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by...
CVE-2018-11137The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now