2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1049MEDIUM5.9In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from ke...
CVE-2018-7188An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges ...
CVE-2018-7187HIGH8.8The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import pa...
CVE-2018-0516Untrusted search path vulnerability in FLET'S v4 / v6 address selection tool allows an attacker to gain privileges via a...
CVE-2018-0515Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to ga...
CVE-2018-7186Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allow...
CVE-2018-6944core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabili...
CVE-2018-6943core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabil...
CVE-2018-1000066Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5380. Reason: This candidate is a reservation du...
CVE-2018-1000065Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5381. Reason: This candidate is a reservation du...
CVE-2018-1000064Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5378. Reason: This candidate is a reservation du...
CVE-2018-1000063Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5379. Reason: This candidate is a reservation du...
CVE-2018-7176FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u...
CVE-2018-6324F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upo...
CVE-2018-6189F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body...
CVE-2018-1000068MEDIUM5.3An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, tha...
CVE-2018-1000067MEDIUM5.3An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that a...
CVE-2018-6316Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authe...
CVE-2018-5767An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code...
CVE-2018-7175An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of...
CVE-2018-7174An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service becau...
CVE-2018-7173A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific...
CVE-2018-7169An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be place...
CVE-2018-7054An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconn...
CVE-2018-7053An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are r...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now