2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-9038Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo...
CVE-2018-9037Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extrac...
CVE-2018-8772Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
CVE-2018-2413MEDIUM5.4SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e...
CVE-2018-2412LOW3.8SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e...
CVE-2018-2410MEDIUM5.4SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross...
CVE-2018-2409MEDIUM6.3Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain ...
CVE-2018-2408HIGH7.3Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Laun...
CVE-2018-2406MEDIUM5.3Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0...
CVE-2018-2405MEDIUM5.4SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an ...
CVE-2018-2404MEDIUM4.3SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
CVE-2018-2403MEDIUM5.4Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise ...
CVE-2018-5227Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attac...
CVE-2018-9934The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a ...
CVE-2018-9928Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web scri...
CVE-2018-9927An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=me...
CVE-2018-9926An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=...
CVE-2018-9925An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&d...
CVE-2018-9924An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp...
CVE-2018-9923An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an artic...
CVE-2018-9922An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field tha...
CVE-2018-9840The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feat...
CVE-2018-5463A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME L...
CVE-2018-6182Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE i...
CVE-2018-1217Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now