2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15799 | — | — | — | Jan 2, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15760 | — | — | — | Jan 2, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-20652 | — | — | 1.5% | Jan 1, 2019 | An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v... |
| CVE-2018-20651 | — | — | 2.3% | Jan 1, 2019 | A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD... |
| CVE-2018-19903 | — | — | 0.7% | Dec 31, 2018 | Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field. |
| CVE-2018-19902 | — | — | 0.6% | Dec 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter. |
| CVE-2018-19901 | — | — | 0.6% | Dec 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter. |
| CVE-2018-19845 | — | — | 0.6% | Dec 31, 2018 | There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16... |
| CVE-2018-19844 | — | — | 0.6% | Dec 31, 2018 | FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related ... |
| CVE-2018-20617 | — | — | 1.1% | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c. |
| CVE-2018-17191 | — | — | 7.8% | Dec 31, 2018 | Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command... |
| CVE-2018-20616 | — | — | 1.1% | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wa... |
| CVE-2018-20614 | — | — | 1.3% | Dec 30, 2018 | public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI... |
| CVE-2018-20613 | — | — | 0.5% | Dec 30, 2018 | TEMMOKU T1.09 Beta allows admin/user/add CSRF. |
| CVE-2018-20612 | — | — | 0.5% | Dec 30, 2018 | UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. |
| CVE-2018-20611 | — | — | 0.9% | Dec 30, 2018 | imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI. |
| CVE-2018-20610 | — | — | 1.9% | Dec 30, 2018 | imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter. |
| CVE-2018-20609 | — | — | 2.7% | Dec 30, 2018 | imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/che... |
| CVE-2018-20608 | — | — | 12.4% | Dec 30, 2018 | imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI. |
| CVE-2018-20607 | — | — | 2.7% | Dec 30, 2018 | imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.p... |
| CVE-2018-20606 | — | — | 2.6% | Dec 30, 2018 | imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI. |
| CVE-2018-20605 | — | — | 2.4% | Dec 30, 2018 | imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.ph... |
| CVE-2018-20604 | — | — | 1.4% | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demon... |
| CVE-2018-20603 | — | — | 0.5% | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF. |
| CVE-2018-20602 | — | — | 1.3% | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now