2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-7204inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /w...
CVE-2018-5452HIGH7.5A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Co...
CVE-2018-7746HIGH8.8An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann...
CVE-2018-7745HIGH7.5An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst...
CVE-2018-7473MEDIUM6.1Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attacke...
CVE-2018-1000119Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF toke...
CVE-2018-1000118Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler...
CVE-2018-1000117MEDIUM6.7Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in o...
CVE-2018-1000116NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command e...
CVE-2018-1054An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all ve...
CVE-2018-7741Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.
CVE-2018-7740The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of...
CVE-2018-7721Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.clas...
CVE-2018-7720HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/create...
CVE-2018-7739antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and ...
CVE-2018-7738In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands ...
CVE-2018-7737In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph...
CVE-2018-7736In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so...
CVE-2018-5471A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1...
CVE-2018-5469An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MAC...
CVE-2018-5467An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MAC...
CVE-2018-5465A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS ...
CVE-2018-5461An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, M...
CVE-2018-7185HIGH7.5The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by ...
CVE-2018-7184ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote atta...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now