Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-8892

Published Dec 20, 2018

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8891

Published Dec 20, 2018

Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script command…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8888

Published Dec 20, 2018

A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that c…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19234

Published Dec 20, 2018

The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19233

Published Dec 20, 2018

COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000882

Published Dec 20, 2018

WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be explo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000881

Published Dec 20, 2018

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that ca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000875

Published Dec 20, 2018

Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerabilit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000874

Published Dec 20, 2018

PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distributed parsers allowing a malicious crafted script to be execute…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000872

Published Dec 20, 2018

OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000871

Published Dec 20, 2018

HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacke…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000870

Published Dec 20, 2018

PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000869

Published Dec 20, 2018

phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000868

Published Dec 20, 2018

WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000867

Published Dec 20, 2018

WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. Th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000860

Published Dec 20, 2018

phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encap…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 16,510 CVEsPage 16 of 661