2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16638 | — | — | 0.6% | Dec 28, 2018 | Evolution CMS 1.4.x allows XSS via the manager/ search parameter. |
| CVE-2018-16637 | — | — | 0.6% | Dec 28, 2018 | Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. |
| CVE-2018-16632 | — | — | 0.6% | Dec 28, 2018 | Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blo... |
| CVE-2018-16630 | — | — | 0.6% | Dec 28, 2018 | Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file. |
| CVE-2018-5204 | — | — | 2.3% | Dec 28, 2018 | ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to d... |
| CVE-2018-5203 | — | — | 2.3% | Dec 28, 2018 | DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download a... |
| CVE-2018-20574 | — | — | 2.5% | Dec 28, 2018 | The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denia... |
| CVE-2018-20573 | — | — | 2.5% | Dec 28, 2018 | The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial ... |
| CVE-2018-20572 | — | — | 1.5% | Dec 28, 2018 | WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=searc... |
| CVE-2018-20571 | — | — | 1.4% | Dec 28, 2018 | DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstra... |
| CVE-2018-20570 | — | — | 2.2% | Dec 28, 2018 | jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. |
| CVE-2018-20569 | — | — | 1.6% | Dec 28, 2018 | user/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authe... |
| CVE-2018-20568 | — | — | 1.6% | Dec 28, 2018 | Administrator/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection ... |
| CVE-2018-20567 | — | — | 1.0% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic... |
| CVE-2018-20566 | — | — | 1.3% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read re... |
| CVE-2018-20565 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter. |
| CVE-2018-20564 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name par... |
| CVE-2018-20563 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name... |
| CVE-2018-20562 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name par... |
| CVE-2018-20561 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter. |
| CVE-2018-20560 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter. |
| CVE-2018-20559 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter. |
| CVE-2018-20558 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter. |
| CVE-2018-20557 | — | — | 0.5% | Dec 28, 2018 | An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter. |
| CVE-2018-20553 | — | — | 1.2% | Dec 28, 2018 | Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now