2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20954 | — | — | 1.1% | Aug 8, 2019 | The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expire... |
| CVE-2018-20962 | — | — | 1.3% | Aug 8, 2019 | The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type. |
| CVE-2018-19855 | — | — | 1.1% | Aug 8, 2019 | UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction... |
| CVE-2018-20961 | CRITICAL | 9.8 | 6.3% | Aug 7, 2019 | In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/func... |
| CVE-2018-14383 | — | — | 1.5% | Aug 7, 2019 | The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML p... |
| CVE-2018-20959 | — | — | 0.6% | Aug 7, 2019 | Jura E8 devices lack Bluetooth connection security. |
| CVE-2018-20958 | — | — | 0.5% | Aug 7, 2019 | The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock op... |
| CVE-2018-4700 | — | — | — | Aug 5, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-4300. Reason: This candidate is a duplicate of C... |
| CVE-2018-1987 | HIGH | 7.8 | 0.3% | Aug 2, 2019 | IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect nod... |
| CVE-2018-20953 | — | — | 0.6% | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). |
| CVE-2018-20952 | — | — | 0.9% | Aug 1, 2019 | cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388). |
| CVE-2018-20951 | — | — | 0.6% | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387). |
| CVE-2018-20950 | — | — | 0.6% | Aug 1, 2019 | cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). |
| CVE-2018-20949 | — | — | 0.6% | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). |
| CVE-2018-20948 | — | — | 0.6% | Aug 1, 2019 | cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383). |
| CVE-2018-20947 | — | — | 0.4% | Aug 1, 2019 | cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). |
| CVE-2018-20946 | — | — | 0.4% | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archi... |
| CVE-2018-20945 | — | — | 0.6% | Aug 1, 2019 | bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). |
| CVE-2018-20944 | — | — | 0.4% | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). |
| CVE-2018-20943 | — | — | 0.3% | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task ... |
| CVE-2018-20942 | — | — | 0.3% | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab... |
| CVE-2018-20941 | — | — | 0.3% | Aug 1, 2019 | cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349). |
| CVE-2018-20940 | — | — | 0.3% | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of bac... |
| CVE-2018-20939 | — | — | 0.4% | Aug 1, 2019 | cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging ... |
| CVE-2018-20938 | — | — | 0.6% | Aug 1, 2019 | cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324). |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now