2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20869cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
CVE-2018-20868cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
CVE-2018-20866cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
CVE-2018-20865cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
CVE-2018-20864cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
CVE-2018-20863cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
CVE-2018-20862cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
CVE-2018-20867cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
CVE-2018-18570Planon before Live Build 41 has XSS.
CVE-2018-11774Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. ...
CVE-2018-11773Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. Th...
CVE-2018-11772Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previo...
CVE-2018-17213An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can by...
CVE-2018-17211An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view de...
CVE-2018-20857Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <...
CVE-2018-20856An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-afte...
CVE-2018-20855LOW3.3An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_...
CVE-2018-20854An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error wi...
CVE-2018-11779In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is pos...
CVE-2018-13897Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Sna...
CVE-2018-3316Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio...
CVE-2018-3315Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio...
CVE-2018-3111Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operati...
CVE-2018-2883Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operati...
CVE-2018-18676GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now