2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1143A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending ...
CVE-2018-9137Open-AudIT before 2.2 has CSV Injection.
CVE-2018-10227MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
CVE-2018-10225thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
CVE-2018-10224An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.htm...
CVE-2018-10223An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/...
CVE-2018-10222An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?ap...
CVE-2018-10221An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator co...
CVE-2018-10220Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intenti...
CVE-2018-10219baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request.
CVE-2018-10205hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in con...
CVE-2018-2879Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). ...
CVE-2018-2878Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Oracle PeopleSoft Products (subcomponent: ...
CVE-2018-2877Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: ndbcluster/plugin). Supported versi...
CVE-2018-2876Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: RIB Kernal(Apa...
CVE-2018-2874Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Logging). The...
CVE-2018-2873Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager...
CVE-2018-2872Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager...
CVE-2018-2871Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supp...
CVE-2018-2870Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supp...
CVE-2018-2869Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supp...
CVE-2018-2868Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supp...
CVE-2018-2867Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics)....
CVE-2018-2866Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy V...
CVE-2018-2865Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy V...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now