2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20969——do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the ...
CVE-2018-14062——The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of servi...
CVE-2018-14672——In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files ...
CVE-2018-14671——In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remo...
CVE-2018-14670——Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
CVE-2018-14669——ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a mali...
CVE-2018-14668——In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat...
CVE-2018-17790MEDIUM5.4Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
CVE-2018-14008——Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
CVE-2018-12357——Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
CVE-2018-12101——CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields...
CVE-2018-19386——SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, ...
CVE-2018-20968——The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
CVE-2018-20967——The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
CVE-2018-20964——The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20963——The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2018-20966——The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-20965MEDIUM6.1The ultimate-member plugin before 2.0.4 for WordPress has XSS.
CVE-2018-20827——The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript ...
CVE-2018-20826MEDIUM4.3The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter ...
CVE-2018-20858——Recommender before 2018-07-18 allows XSS.
CVE-2018-20960——Nespresso Prodigio devices lack Bluetooth connection security.
CVE-2018-20957——The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
CVE-2018-20956——Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by...
CVE-2018-20955——Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now