2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19349 | — | — | 1.0% | Nov 17, 2018 | In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkh... |
| CVE-2018-19348 | — | — | 2.0% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19347 | — | — | 1.7% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19346 | — | — | 1.7% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19345 | — | — | 1.7% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19344 | — | — | 1.7% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19343 | — | — | 1.7% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19342 | — | — | 2.0% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19341 | — | — | 1.7% | Nov 17, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-19340 | — | — | 0.7% | Nov 17, 2018 | Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, Ship... |
| CVE-2018-19333 | — | — | 0.8% | Nov 17, 2018 | pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in proces... |
| CVE-2018-19332 | — | — | 0.5% | Nov 17, 2018 | An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type... |
| CVE-2018-19331 | — | — | 1.1% | Nov 17, 2018 | An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter. |
| CVE-2018-19329 | — | — | 1.8% | Nov 17, 2018 | GreenCMS v2.3.0603 allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pa... |
| CVE-2018-19328 | — | — | 1.8% | Nov 17, 2018 | LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal. |
| CVE-2018-19327 | — | — | 0.5% | Nov 17, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF. |
| CVE-2018-19326 | — | — | 8.2% | Nov 17, 2018 | Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd. |
| CVE-2018-19324 | — | — | 0.5% | Nov 17, 2018 | kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI. |
| CVE-2018-18955 | — | — | 7.6% | Nov 16, 2018 | In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat... |
| CVE-2018-19319 | — | — | 0.4% | Nov 16, 2018 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's pri... |
| CVE-2018-19318 | — | — | 0.5% | Nov 16, 2018 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super admini... |
| CVE-2018-19312 | — | — | 1.9% | Nov 16, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to th... |
| CVE-2018-19311 | — | — | 1.2% | Nov 16, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated... |
| CVE-2018-18806 | — | — | 1.6% | Nov 16, 2018 | School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb. |
| CVE-2018-18804 | — | — | 3.2% | Nov 16, 2018 | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now