2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18841 | — | — | 0.5% | Oct 30, 2018 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter. |
| CVE-2018-18840 | — | — | 0.6% | Oct 30, 2018 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter. |
| CVE-2018-18835 | — | — | 1.6% | Oct 30, 2018 | upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via... |
| CVE-2018-18834 | — | — | 2.1% | Oct 30, 2018 | An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/a... |
| CVE-2018-18832 | — | — | 1.3% | Oct 30, 2018 | admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp. |
| CVE-2018-18831 | — | — | 1.5% | Oct 30, 2018 | An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file... |
| CVE-2018-18830 | — | — | 1.2% | Oct 30, 2018 | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does ... |
| CVE-2018-18829 | — | — | 0.9% | Oct 30, 2018 | There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers ... |
| CVE-2018-18828 | — | — | 0.9% | Oct 30, 2018 | There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers... |
| CVE-2018-18827 | — | — | 0.9% | Oct 30, 2018 | There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cau... |
| CVE-2018-18826 | — | — | 0.9% | Oct 30, 2018 | There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers ... |
| CVE-2018-18825 | — | — | 0.7% | Oct 30, 2018 | Pagoda Linux panel V6.0 has XSS via the verification code associated with an invalid account login. A crafted code is mi... |
| CVE-2018-18822 | — | — | 1.6% | Oct 30, 2018 | Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter. |
| CVE-2018-18817 | — | — | 1.1% | Oct 30, 2018 | The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote atta... |
| CVE-2018-17706 | — | — | 2.8% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF Pha... |
| CVE-2018-17624 | — | — | 3.3% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5... |
| CVE-2018-17623 | — | — | 3.3% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17621 | — | — | 3.6% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17620 | — | — | 3.8% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17619 | — | — | 3.8% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17618 | — | — | 3.3% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17617 | — | — | 3.8% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17616 | — | — | 3.8% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-17615 | — | — | 3.3% | Oct 29, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5... |
| CVE-2018-18387 | — | — | 1.8% | Oct 29, 2018 | playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now