2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18790 | — | — | 1.1% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This nee... |
| CVE-2018-18789 | — | — | 1.2% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. |
| CVE-2018-18788 | — | — | 1.1% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This n... |
| CVE-2018-18787 | — | — | 1.2% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. |
| CVE-2018-18786 | — | — | 1.2% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. |
| CVE-2018-18785 | — | — | 1.2% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. |
| CVE-2018-18784 | — | — | 1.1% | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This need... |
| CVE-2018-18783 | — | — | 0.8% | Oct 29, 2018 | XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter. |
| CVE-2018-18782 | — | — | 0.8% | Oct 29, 2018 | Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter. |
| CVE-2018-18781 | — | — | 0.7% | Oct 29, 2018 | DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter. |
| CVE-2018-18778 | — | — | 74.0% | Oct 29, 2018 | ACME mini_httpd before 1.30 lets remote users read arbitrary files. |
| CVE-2018-18771 | — | — | 0.9% | Oct 29, 2018 | An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php al... |
| CVE-2018-18765 | — | — | 1.8% | Oct 29, 2018 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6... |
| CVE-2018-18764 | — | — | 1.8% | Oct 29, 2018 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6... |
| CVE-2018-18754 | — | — | 1.1% | Oct 29, 2018 | ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/def... |
| CVE-2018-18753 | — | — | 3.5% | Oct 29, 2018 | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. |
| CVE-2018-18752 | — | — | 2.3% | Oct 29, 2018 | Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/Ws... |
| CVE-2018-18751 | — | — | 4.3% | Oct 29, 2018 | An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related ... |
| CVE-2018-18748 | — | — | 2.4% | Oct 29, 2018 | Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershe... |
| CVE-2018-18745 | — | — | 0.5% | Oct 29, 2018 | An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing. |
| CVE-2018-18744 | — | — | 0.5% | Oct 29, 2018 | An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI. |
| CVE-2018-18743 | — | — | 0.5% | Oct 29, 2018 | An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI. |
| CVE-2018-18742 | — | — | 0.5% | Oct 29, 2018 | A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI. |
| CVE-2018-18741 | — | — | 0.5% | Oct 29, 2018 | An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing. |
| CVE-2018-18740 | — | — | 0.5% | Oct 29, 2018 | An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now