2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3734HIGH7.5stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malici...
CVE-2018-3733HIGH7.5crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url...
CVE-2018-11392An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4....
CVE-2018-11027A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTM...
CVE-2018-10751A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex...
CVE-2018-10466Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
CVE-2018-1495MEDIUM6.5IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitr...
CVE-2018-1242Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command inj...
CVE-2018-1241Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditio...
CVE-2018-1235Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje...
CVE-2018-5241Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authenticati...
CVE-2018-1376MEDIUM6.1IBM Security Guardium Big Data Intelligence (SonarG) 3.1 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2018-1375MEDIUM5.9IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentica...
CVE-2018-1370MEDIUM4.2IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way...
CVE-2018-1369LOW3.7IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead t...
CVE-2018-11536md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.
CVE-2018-11535An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users....
CVE-2018-11532An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst...
CVE-2018-11531Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
CVE-2018-11528WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
CVE-2018-11527An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php al...
CVE-2018-11523upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
CVE-2018-11488A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cau...
CVE-2018-10732The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a u...
CVE-2018-11517mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter valu...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now