2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11342A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily spe...
CVE-2018-11341Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via...
CVE-2018-11340An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload...
CVE-2018-11339An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
CVE-2018-11331An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filet...
CVE-2018-11330An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames...
CVE-2018-1108MEDIUM5.9kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed ...
CVE-2018-7687HIGH7.8The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevat...
CVE-2018-8012HIGH7.5No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, a...
CVE-2018-8010This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in So...
CVE-2018-1067MEDIUM6.1In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow ...
CVE-2018-7268MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information e...
CVE-2018-11320In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive va...
CVE-2018-11096Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the ta...
CVE-2018-11092An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin not...
CVE-2018-8142A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feat...
CVE-2018-11311A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack...
CVE-2018-11319Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the c...
CVE-2018-11242An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte...
CVE-2018-11315The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS reb...
CVE-2018-11239An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 to...
CVE-2018-4994Adobe Connect versions 9.7.5 and earlier have an exploitable Authentication Bypass vulnerability. Successful exploitatio...
CVE-2018-4992Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vu...
CVE-2018-4991Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validat...
CVE-2018-4944Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploita...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now