2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20887cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
CVE-2018-20886cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418).
CVE-2018-11892Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2018-10899HIGH8.1A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. T...
CVE-2018-20885cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (S...
CVE-2018-20884cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
CVE-2018-20883cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
CVE-2018-20882cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password...
CVE-2018-20881cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
CVE-2018-20880cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
CVE-2018-20879cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
CVE-2018-20878cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
CVE-2018-20877cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
CVE-2018-20876cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
CVE-2018-20875cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
CVE-2018-20874cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
CVE-2018-20873cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
CVE-2018-20872DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.
CVE-2018-16860HIGH7.5A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4...
CVE-2018-20871In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissi...
CVE-2018-20861libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.
CVE-2018-20860MEDIUM6.5libopenmpt before 0.3.13 allows a crash with malformed MED files.
CVE-2018-20859MEDIUM6.1edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
CVE-2018-16871HIGH7.5A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker...
CVE-2018-20870The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now