2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-7563An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preferenc...
CVE-2018-7562A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary acce...
CVE-2018-7538A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a...
CVE-2018-6623An issue was discovered in Hola 1.79.859. An unprivileged user could modify or overwrite the executable with arbitrary c...
CVE-2018-6400Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating...
CVE-2018-6322Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all t...
CVE-2018-6321Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows l...
CVE-2018-6183BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all ...
CVE-2018-6016Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows ...
CVE-2018-5758The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity ...
CVE-2018-7749The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed befo...
CVE-2018-1206Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to ...
CVE-2018-1323The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path b...
CVE-2018-8070QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI.
CVE-2018-8069QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI.
CVE-2018-8065An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v...
CVE-2018-8058CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
CVE-2018-7893CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
CVE-2018-8059The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involv...
CVE-2018-8057A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a...
CVE-2018-8056Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma...
CVE-2018-8050The af_get_page() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to ca...
CVE-2018-7213The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authen...
CVE-2018-8043The unimac_mdio_probe function in drivers/net/phy/mdio-bcm-unimac.c in the Linux kernel through 4.15.8 does not validate...
CVE-2018-6312HIGH7.2A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now