2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1083Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unpr...
CVE-2018-9109CRITICAL9.1Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function...
CVE-2018-9108CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account w...
CVE-2018-9107CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing exte...
CVE-2018-9106CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio...
CVE-2018-8823modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for Pre...
CVE-2018-9105NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privil...
CVE-2018-9092There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
CVE-2018-9058In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers c...
CVE-2018-1327The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a m...
CVE-2018-1238Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA)....
CVE-2018-1237Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light i...
CVE-2018-1205Dell EMC ScaleIO, versions prior to 2.5, do not properly handle some packet data in the MDM service. As a result, a remo...
CVE-2018-1091In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel...
CVE-2018-0739Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack gi...
CVE-2018-0733Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least s...
CVE-2018-9057aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0...
CVE-2018-7700DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php...
CVE-2018-9056Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an atta...
CVE-2018-8048In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing ...
CVE-2018-7196MEDIUM6.1Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers...
CVE-2018-7195HIGH8.1Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail addre...
CVE-2018-7194MEDIUM4.9Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attacker...
CVE-2018-7193MEDIUM6.1Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attac...
CVE-2018-7192MEDIUM6.1Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remot...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now