2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-8035This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache ...
CVE-2018-17606Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16620. Reason: This candidate is a reservation d...
CVE-2018-20835A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball co...
CVE-2018-20834A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue ...
CVE-2018-15208BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
CVE-2018-15207BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a norm...
CVE-2018-15206BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
CVE-2018-14931An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exis...
CVE-2018-14930An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebA...
CVE-2018-14875An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists ...
CVE-2018-14874An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code pa...
CVE-2018-20510The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users...
CVE-2018-20509The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obta...
CVE-2018-19374Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Troj...
CVE-2018-5123A third party website can access information available to a user with access to a restricted bug entry using the image g...
CVE-2018-12384When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-ze...
CVE-2018-18276XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the ad...
CVE-2018-15584Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboar...
CVE-2018-15582Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gn...
CVE-2018-15581Cross-Site Scripting (XSS) vulnerability in adm/faqmasterformupdate.php in gnuboard5 before 5.3.1.6 allows remote attack...
CVE-2018-15580Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attacker...
CVE-2018-5124Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox bef...
CVE-2018-18513A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be...
CVE-2018-18512A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound...
CVE-2018-18511Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImage...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now