2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5226 | — | — | 1.5% | Apr 25, 2018 | There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going ... |
| CVE-2018-1339 | — | — | 2.6% | Apr 25, 2018 | A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika ... |
| CVE-2018-1338 | — | — | 2.0% | Apr 25, 2018 | A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika ... |
| CVE-2018-1335 | — | — | 94.1% | Apr 25, 2018 | From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to... |
| CVE-2018-9104 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-9103 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-9102 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-9101 | — | — | 1.1% | Apr 25, 2018 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earli... |
| CVE-2018-8716 | — | — | 39.3% | Apr 25, 2018 | WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. |
| CVE-2018-10213 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a di... |
| CVE-2018-10212 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creatio... |
| CVE-2018-10211 | — | — | 1.1% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the h... |
| CVE-2018-10210 | — | — | 1.1% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the passw... |
| CVE-2018-10209 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download... |
| CVE-2018-10208 | — | — | 0.8% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page... |
| CVE-2018-10207 | — | — | 1.1% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on t... |
| CVE-2018-10206 | — | — | 0.6% | Apr 25, 2018 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field... |
| CVE-2018-1363 | — | — | 1.0% | Apr 25, 2018 | IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vul... |
| CVE-2018-1112 | HIGH | 8 | 2.4% | Apr 25, 2018 | glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenti... |
| CVE-2018-8801 | — | — | 1.3% | Apr 25, 2018 | GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and w... |
| CVE-2018-10376 | — | — | 1.8% | Apr 25, 2018 | An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereu... |
| CVE-2018-10375 | — | — | 1.2% | Apr 25, 2018 | A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized b... |
| CVE-2018-10374 | — | — | 0.7% | Apr 25, 2018 | EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request... |
| CVE-2018-10373 | — | — | 3.5% | Apr 25, 2018 | concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.3... |
| CVE-2018-10372 | — | — | 2.4% | Apr 25, 2018 | process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buf... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now