2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15518 | — | — | 2.5% | Dec 26, 2018 | QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML doc... |
| CVE-2018-20486 | — | — | 0.7% | Dec 26, 2018 | MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter. |
| CVE-2018-20485 | — | — | 5.3% | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. |
| CVE-2018-20484 | — | — | 5.3% | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. |
| CVE-2018-20483 | — | — | 0.7% | Dec 26, 2018 | set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata at... |
| CVE-2018-0724 | — | — | 0.8% | Dec 26, 2018 | Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote ... |
| CVE-2018-0723 | — | — | 0.8% | Dec 26, 2018 | Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote ... |
| CVE-2018-20481 | — | — | 3.4% | Dec 26, 2018 | XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause ... |
| CVE-2018-20480 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter. |
| CVE-2018-20479 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter. |
| CVE-2018-20478 | — | — | 1.2% | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.p... |
| CVE-2018-20477 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field. |
| CVE-2018-20476 | — | — | 0.7% | Dec 26, 2018 | An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter. |
| CVE-2018-20465 | — | — | 1.1% | Dec 25, 2018 | Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side templa... |
| CVE-2018-20464 | — | — | 0.7% | Dec 25, 2018 | There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered... |
| CVE-2018-20463 | — | — | 13.4% | Dec 25, 2018 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../... |
| CVE-2018-20462 | — | — | 4.0% | Dec 25, 2018 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows rem... |
| CVE-2018-20461 | — | — | 1.0% | Dec 25, 2018 | In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (applic... |
| CVE-2018-20460 | — | — | 1.1% | Dec 25, 2018 | In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial... |
| CVE-2018-20456 | — | — | 1.0% | Dec 25, 2018 | In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denia... |
| CVE-2018-20455 | — | — | 1.0% | Dec 25, 2018 | In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denia... |
| CVE-2018-20454 | — | — | 0.7% | Dec 25, 2018 | An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter. |
| CVE-2018-20453 | — | — | 0.9% | Dec 25, 2018 | The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers ... |
| CVE-2018-20452 | — | — | 1.5% | Dec 25, 2018 | The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of serv... |
| CVE-2018-20450 | — | — | 1.1% | Dec 25, 2018 | The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (ap... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now