2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18530 | — | — | 1.2% | Oct 19, 2018 | ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mish... |
| CVE-2018-18529 | — | — | 1.2% | Oct 19, 2018 | ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey fu... |
| CVE-2018-18380 | — | — | 1.1% | Oct 19, 2018 | A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID inste... |
| CVE-2018-18527 | — | — | 1.6% | Oct 19, 2018 | OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter. |
| CVE-2018-18396 | — | — | 2.3% | Oct 19, 2018 | Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. |
| CVE-2018-18395 | — | — | 1.5% | Oct 19, 2018 | Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. |
| CVE-2018-18394 | — | — | 0.7% | Oct 19, 2018 | Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions versi... |
| CVE-2018-18393 | — | — | 1.0% | Oct 19, 2018 | Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. |
| CVE-2018-18392 | — | — | 1.0% | Oct 19, 2018 | Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions v... |
| CVE-2018-18391 | — | — | 1.0% | Oct 19, 2018 | User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. |
| CVE-2018-18390 | — | — | 1.1% | Oct 19, 2018 | User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. |
| CVE-2018-15316 | — | — | 0.6% | Oct 19, 2018 | In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client compo... |
| CVE-2018-15315 | — | — | 0.9% | Oct 19, 2018 | On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vulnerability in an un... |
| CVE-2018-15314 | — | — | 1.4% | Oct 19, 2018 | On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undiscl... |
| CVE-2018-15313 | — | — | 1.4% | Oct 19, 2018 | On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undiscl... |
| CVE-2018-15312 | — | — | 0.9% | Oct 19, 2018 | On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undi... |
| CVE-2018-18488 | — | — | 1.1% | Oct 18, 2018 | In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. |
| CVE-2018-18487 | — | — | 1.2% | Oct 18, 2018 | In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafel... |
| CVE-2018-18486 | — | — | 1.1% | Oct 18, 2018 | An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter. |
| CVE-2018-18485 | — | — | 1.8% | Oct 18, 2018 | An issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via di... |
| CVE-2018-18484 | — | — | 1.9% | Oct 18, 2018 | An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs ... |
| CVE-2018-18483 | — | — | 2.4% | Oct 18, 2018 | The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to ... |
| CVE-2018-18482 | — | — | 1.1% | Oct 18, 2018 | An issue was discovered in libpg_query 10-1.0.2. There is a memory leak in pg_query_raw_parse in pg_query_parse.c, which... |
| CVE-2018-18481 | — | — | 1.1% | Oct 18, 2018 | A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/dwg/io.cpp, resulting in an app... |
| CVE-2018-18480 | — | — | 1.1% | Oct 18, 2018 | A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadMCHAR function in lib/dwg/io.cpp, resulting in an ap... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now