2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18675GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board titl...
CVE-2018-18672GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head conten...
CVE-2018-18670GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" p...
CVE-2018-18673GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parame...
CVE-2018-18671GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head...
CVE-2018-18669GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title conte...
CVE-2018-2024HIGH8.1IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to...
CVE-2018-13927Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel ...
CVE-2018-13924Lack of check to prevent the buffer length taking negative values can lead to stack overflow. in Snapdragon Auto, Snapdr...
CVE-2018-13896XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to ...
CVE-2018-17210An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and lau...
CVE-2018-17792MDaemon Webmail (formerly WorldClient) has CSRF.
CVE-2018-2022MEDIUM5.3IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount ...
CVE-2018-2021MEDIUM6.1IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2018-1921MEDIUM5.4IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2018-13442SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts T...
CVE-2018-19629A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows...
CVE-2018-7838HIGH7.5A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Et...
CVE-2018-20852http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validat...
CVE-2018-18095Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 ma...
CVE-2018-17196In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses t...
CVE-2018-1968MEDIUM5.3IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used t...
CVE-2018-19588Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
CVE-2018-17152Intersystems Cache 2017.2.2.865.0 allows XXE.
CVE-2018-17151Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now