Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-20300

Published Dec 20, 2018

Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15801

Published Dec 19, 2018

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an hone…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15798

Published Dec 19, 2018

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a li…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11799

Published Dec 19, 2018

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19598

Published Dec 19, 2018

Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19596

Published Dec 19, 2018

Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19508

Published Dec 19, 2018

CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19506

Published Dec 19, 2018

Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20298

Published Dec 19, 2018

S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user int…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15127

Published Dec 19, 2018

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code…

CVSS 9.8 · Critical

CVE-2018-17195

Published Dec 19, 2018

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17194

Published Dec 19, 2018

When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17193

Published Dec 19, 2018

The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to corr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 16,510 CVEsPage 20 of 661