2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19552 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. |
| CVE-2018-19551 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags... |
| CVE-2018-19550 | — | — | 6.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit ... |
| CVE-2018-19549 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php. |
| CVE-2018-19548 | — | — | 1.7% | Nov 26, 2018 | index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm... |
| CVE-2018-19547 | — | — | 0.7% | Nov 26, 2018 | JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter. |
| CVE-2018-19546 | — | — | 0.5% | Nov 26, 2018 | JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload... |
| CVE-2018-19545 | — | — | 0.5% | Nov 26, 2018 | JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. |
| CVE-2018-19544 | — | — | 0.4% | Nov 26, 2018 | JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. |
| CVE-2018-19543 | — | — | 1.6% | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in... |
| CVE-2018-19542 | — | — | 1.9% | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp... |
| CVE-2018-19541 | — | — | 2.8% | Nov 26, 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16... |
| CVE-2018-19540 | — | — | 2.3% | Nov 26, 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16... |
| CVE-2018-19539 | — | — | 1.9% | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/b... |
| CVE-2018-19537 | — | — | 6.0% | Nov 26, 2018 | TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_ho... |
| CVE-2018-19532 | — | — | 1.7% | Nov 26, 2018 | A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoF... |
| CVE-2018-19531 | — | — | 4.6% | Nov 26, 2018 | HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function us... |
| CVE-2018-19530 | — | — | 4.6% | Nov 26, 2018 | HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function us... |
| CVE-2018-19528 | — | — | 2.7% | Nov 26, 2018 | TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted... |
| CVE-2018-19520 | — | — | 2.9% | Nov 25, 2018 | An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in... |
| CVE-2018-19519 | — | — | 2.4% | Nov 25, 2018 | In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet ... |
| CVE-2018-19517 | — | — | 0.8% | Nov 24, 2018 | An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a m... |
| CVE-2018-19504 | — | — | 1.4% | Nov 23, 2018 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilt... |
| CVE-2018-19503 | — | — | 1.5% | Nov 23, 2018 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in t... |
| CVE-2018-19502 | — | — | 1.5% | Nov 23, 2018 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in th... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now