2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19141 | — | — | 0.7% | Nov 11, 2018 | Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack v... |
| CVE-2018-19135 | — | — | 3.0% | Nov 11, 2018 | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an ... |
| CVE-2018-19168 | — | — | 6.5% | Nov 11, 2018 | Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows re... |
| CVE-2018-19150 | — | — | 1.2% | Nov 10, 2018 | Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to caus... |
| CVE-2018-19149 | — | — | 2.7% | Nov 10, 2018 | Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_atta... |
| CVE-2018-19148 | — | — | 0.9% | Nov 10, 2018 | Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumer... |
| CVE-2018-19087 | — | — | 0.6% | Nov 10, 2018 | RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0... |
| CVE-2018-19086 | — | — | 0.6% | Nov 10, 2018 | RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0... |
| CVE-2018-19085 | — | — | 0.6% | Nov 10, 2018 | RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0... |
| CVE-2018-19084 | — | — | 0.6% | Nov 10, 2018 | RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0... |
| CVE-2018-19145 | — | — | 0.7% | Nov 9, 2018 | An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter. |
| CVE-2018-19139 | — | — | 1.7% | Nov 9, 2018 | An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jp... |
| CVE-2018-19138 | — | — | 2.2% | Nov 9, 2018 | WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI. |
| CVE-2018-17612 | — | — | 6.7% | Nov 9, 2018 | Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the loc... |
| CVE-2018-19137 | — | — | 2.4% | Nov 9, 2018 | DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter. |
| CVE-2018-19136 | — | — | 6.0% | Nov 9, 2018 | DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter. |
| CVE-2018-19127 | — | — | 20.8% | Nov 9, 2018 | A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cach... |
| CVE-2018-19133 | — | — | 1.2% | Nov 9, 2018 | In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address. |
| CVE-2018-19132 | — | — | 6.1% | Nov 9, 2018 | Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. |
| CVE-2018-19131 | — | — | 3.3% | Nov 9, 2018 | Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. |
| CVE-2018-19130 | — | — | 1.1% | Nov 9, 2018 | In Libav 12.3, there is an invalid memory access in vc1_decode_frame in libavcodec/vc1dec.c that allows attackers to cau... |
| CVE-2018-19129 | — | — | 0.9% | Nov 9, 2018 | In Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in ff_mpa_synth_filter_float in libavcodec/mpegaudi... |
| CVE-2018-19128 | — | — | 1.1% | Nov 9, 2018 | In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to ... |
| CVE-2018-19126 | — | — | 22.5% | Nov 9, 2018 | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u... |
| CVE-2018-19125 | — | — | 10.8% | Nov 9, 2018 | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now