2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19499 | — | — | 2.0% | Nov 23, 2018 | Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a rea... |
| CVE-2018-19492 | — | — | 1.6% | Nov 23, 2018 | An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with a... |
| CVE-2018-19491 | — | — | 1.6% | Nov 23, 2018 | An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an... |
| CVE-2018-19490 | — | — | 1.6% | Nov 23, 2018 | An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer ove... |
| CVE-2018-19486 | — | — | 4.1% | Nov 23, 2018 | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $... |
| CVE-2018-19477 | — | — | 3.0% | Nov 23, 2018 | psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because ... |
| CVE-2018-19476 | — | — | 3.0% | Nov 23, 2018 | psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of ... |
| CVE-2018-19475 | — | — | 9.5% | Nov 23, 2018 | psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because... |
| CVE-2018-19469 | — | — | 0.6% | Nov 23, 2018 | ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter. |
| CVE-2018-19468 | — | — | 1.1% | Nov 23, 2018 | HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the u... |
| CVE-2018-19463 | — | — | 2.2% | Nov 22, 2018 | zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by us... |
| CVE-2018-19459 | — | — | 4.0% | Nov 22, 2018 | Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file. |
| CVE-2018-19458 | — | — | 32.9% | Nov 22, 2018 | In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR... |
| CVE-2018-19457 | — | — | 3.9% | Nov 22, 2018 | Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faq... |
| CVE-2018-19443 | — | — | 0.9% | Nov 22, 2018 | The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under cert... |
| CVE-2018-19437 | — | — | 1.1% | Nov 22, 2018 | UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] ... |
| CVE-2018-19436 | — | — | 1.1% | Nov 22, 2018 | An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injecti... |
| CVE-2018-19435 | — | — | 1.1% | Nov 22, 2018 | An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy paramet... |
| CVE-2018-19434 | — | — | 1.1% | Nov 22, 2018 | An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.... |
| CVE-2018-19433 | — | — | 0.9% | Nov 22, 2018 | ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value. |
| CVE-2018-19432 | — | — | 3.0% | Nov 22, 2018 | An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfil... |
| CVE-2018-19424 | — | — | 1.8% | Nov 21, 2018 | ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files. |
| CVE-2018-19421 | — | — | 0.8% | Nov 21, 2018 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file,... |
| CVE-2018-19420 | — | — | 0.8% | Nov 21, 2018 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can ... |
| CVE-2018-19417 | — | — | 5.7% | Nov 21, 2018 | An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now