2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20017 | — | — | 0.6% | Dec 10, 2018 | SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI. |
| CVE-2018-20015 | — | — | 0.5% | Dec 10, 2018 | YzmCMS v5.2 has admin/role/add.html CSRF. |
| CVE-2018-20012 | — | — | 0.5% | Dec 10, 2018 | PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI. |
| CVE-2018-20011 | — | — | 4.4% | Dec 10, 2018 | DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. |
| CVE-2018-20010 | — | — | 4.4% | Dec 10, 2018 | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. |
| CVE-2018-20009 | — | — | 4.4% | Dec 10, 2018 | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. |
| CVE-2018-20006 | — | — | 0.6% | Dec 10, 2018 | An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post... |
| CVE-2018-20005 | — | — | 1.1% | Dec 10, 2018 | An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonst... |
| CVE-2018-20002 | — | — | 1.8% | Dec 10, 2018 | The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distri... |
| CVE-2018-20001 | — | — | 1.0% | Dec 10, 2018 | In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits)... |
| CVE-2018-20000 | — | — | 1.7% | Dec 10, 2018 | Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a loca... |
| CVE-2018-19991 | — | — | 2.3% | Dec 10, 2018 | VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler... |
| CVE-2018-19983 | — | — | 0.5% | Dec 9, 2018 | An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmis... |
| CVE-2018-19982 | — | — | 0.2% | Dec 9, 2018 | An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication a... |
| CVE-2018-19653 | — | — | 1.2% | Dec 9, 2018 | HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing sett... |
| CVE-2018-19980 | — | — | 1.2% | Dec 8, 2018 | Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying A... |
| CVE-2018-19967 | — | — | 0.5% | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of servic... |
| CVE-2018-19966 | — | — | 0.4% | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash... |
| CVE-2018-19965 | — | — | 0.4% | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS cr... |
| CVE-2018-19964 | — | — | 0.4% | Dec 8, 2018 | An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because th... |
| CVE-2018-19963 | — | — | 0.4% | Dec 8, 2018 | An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly... |
| CVE-2018-19962 | — | — | 0.4% | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS pri... |
| CVE-2018-19961 | — | — | 0.4% | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS pri... |
| CVE-2018-9519 | — | — | 0.1% | Dec 7, 2018 | In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to l... |
| CVE-2018-9518 | — | — | 0.3% | Dec 7, 2018 | In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. T... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now