2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20601 | — | — | 0.6% | Dec 30, 2018 | UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action. |
| CVE-2018-20600 | — | — | 0.7% | Dec 30, 2018 | sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action. |
| CVE-2018-20599 | — | — | 1.5% | Dec 30, 2018 | UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileed... |
| CVE-2018-20598 | — | — | 0.5% | Dec 30, 2018 | UCMS 1.4.7 has ?do=user_addpost CSRF. |
| CVE-2018-20597 | — | — | 0.6% | Dec 30, 2018 | UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action. |
| CVE-2018-20596 | — | — | 1.1% | Dec 30, 2018 | Jspxcms v9.0.0 allows SSRF. |
| CVE-2018-20595 | — | — | 0.6% | Dec 30, 2018 | A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because th... |
| CVE-2018-20594 | — | — | 0.9% | Dec 30, 2018 | An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checkin... |
| CVE-2018-20593 | — | — | 1.3% | Dec 30, 2018 | In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c. |
| CVE-2018-20592 | — | — | 1.5% | Dec 30, 2018 | In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attacker... |
| CVE-2018-20591 | — | — | 1.1% | Dec 30, 2018 | A heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted ... |
| CVE-2018-20589 | — | — | 0.6% | Dec 30, 2018 | Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/add_pictures.php a... |
| CVE-2018-20588 | — | — | 1.1% | Dec 30, 2018 | lib/support/unicodeconv/unicodeconv.c in libotfcc.a in otfcc v0.10.3-alpha has a buffer over-read. |
| CVE-2018-20583 | — | — | 1.6% | Dec 30, 2018 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18... |
| CVE-2018-1181 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15794 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15793 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15792 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15791 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15790 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15789 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15788 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15787 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15786 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15785 | — | — | — | Dec 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now