2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20725 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping o... |
| CVE-2018-20724 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of uninte... |
| CVE-2018-20723 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping o... |
| CVE-2018-20720 | — | — | 2.5% | Jan 16, 2019 | ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause... |
| CVE-2018-7603 | — | — | 0.8% | Jan 15, 2019 | In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerabilit... |
| CVE-2018-1772 | — | — | 1.0% | Jan 15, 2019 | IBM SPSS Analytic Server 3.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2018-20719 | — | — | 1.0% | Jan 15, 2019 | In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history p... |
| CVE-2018-20718 | — | — | 3.7% | Jan 15, 2019 | In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:... |
| CVE-2018-20717 | — | — | 2.7% | Jan 15, 2019 | In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a ... |
| CVE-2018-20716 | — | — | 1.2% | Jan 15, 2019 | CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. |
| CVE-2018-20715 | — | — | 1.1% | Jan 15, 2019 | The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the... |
| CVE-2018-20714 | — | — | 1.8% | Jan 15, 2019 | The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vuln... |
| CVE-2018-20713 | — | — | 1.1% | Jan 15, 2019 | Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404. |
| CVE-2018-20712 | — | — | 2.7% | Jan 15, 2019 | A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in... |
| CVE-2018-20703 | — | — | 0.6% | Jan 13, 2019 | CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. |
| CVE-2018-16206 | — | — | 1.0% | Jan 13, 2019 | Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject a... |
| CVE-2018-20699 | — | — | 2.2% | Jan 12, 2019 | Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large intege... |
| CVE-2018-4330 | — | — | 3.1% | Jan 11, 2019 | In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling. |
| CVE-2018-4298 | — | — | 1.3% | Jan 11, 2019 | In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permiss... |
| CVE-2018-4281 | — | — | 1.0% | Jan 11, 2019 | In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation. |
| CVE-2018-4278 | — | — | 2.3% | Jan 11, 2019 | In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows befor... |
| CVE-2018-4277 | — | — | 1.9% | Jan 11, 2019 | In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, ... |
| CVE-2018-4262 | — | — | 2.6% | Jan 11, 2019 | In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows befor... |
| CVE-2018-4258 | — | — | 1.3% | Jan 11, 2019 | In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking. |
| CVE-2018-4257 | — | — | 1.3% | Jan 11, 2019 | In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now