2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20869——cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
CVE-2018-20868——cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
CVE-2018-20866——cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
CVE-2018-20865——cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
CVE-2018-20864——cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
CVE-2018-20863——cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
CVE-2018-20862——cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
CVE-2018-20867——cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
CVE-2018-18570——Planon before Live Build 41 has XSS.
CVE-2018-11774——Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. ...
CVE-2018-11773——Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. Th...
CVE-2018-11772——Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previo...
CVE-2018-17213——An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can by...
CVE-2018-17211——An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view de...
CVE-2018-20857——Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <...
CVE-2018-20856——An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-afte...
CVE-2018-20855LOW3.3An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_...
CVE-2018-20854——An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error wi...
CVE-2018-11779——In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is pos...
CVE-2018-13897——Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Sna...
CVE-2018-3316——Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio...
CVE-2018-3315——Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio...
CVE-2018-3111——Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operati...
CVE-2018-2883——Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operati...
CVE-2018-18676——GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now