2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1000016Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17383. Reason: This candidate is a reservation...
CVE-2018-1000015On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Bui...
CVE-2018-1000014Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, result...
CVE-2018-1000013Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vu...
CVE-2018-1000012Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process...
CVE-2018-1000011Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process...
CVE-2018-1000010Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, all...
CVE-2018-1000009Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build proce...
CVE-2018-1000008Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, all...
CVE-2018-6029The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the con...
CVE-2018-6022Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authen...
CVE-2018-6014Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrie...
CVE-2018-6013Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the dire...
CVE-2018-0862Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro...
CVE-2018-0849Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro...
CVE-2018-0848Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro...
CVE-2018-0845Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro...
CVE-2018-6010In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messa...
CVE-2018-6009In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a...
CVE-2018-6003HIGH7.5An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited rec...
CVE-2018-6002The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\temp...
CVE-2018-6001The Soundy Audio Playlist plugin 4.6 and below for WordPress has Cross-Site Scripting via soundy-audio-playlist\template...
CVE-2018-6000An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn...
CVE-2018-5999An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro...
CVE-2018-1000003Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-mi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now