2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20969do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the ...
CVE-2018-14062The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of servi...
CVE-2018-14672In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files ...
CVE-2018-14671In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remo...
CVE-2018-14670Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
CVE-2018-14669ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a mali...
CVE-2018-14668In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat...
CVE-2018-17790MEDIUM5.4Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
CVE-2018-14008Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
CVE-2018-12357Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
CVE-2018-12101CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields...
CVE-2018-19386SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, ...
CVE-2018-20968The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
CVE-2018-20967The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
CVE-2018-20964The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20963The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2018-20966The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-20965MEDIUM6.1The ultimate-member plugin before 2.0.4 for WordPress has XSS.
CVE-2018-20827The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript ...
CVE-2018-20826MEDIUM4.3The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter ...
CVE-2018-20858Recommender before 2018-07-18 allows XSS.
CVE-2018-20960Nespresso Prodigio devices lack Bluetooth connection security.
CVE-2018-20957The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
CVE-2018-20956Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by...
CVE-2018-20955Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now