2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16635 | — | — | 0.6% | Dec 10, 2018 | Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. |
| CVE-2018-15805 | — | — | 1.6% | Dec 10, 2018 | Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an att... |
| CVE-2018-15800 | HIGH | 8.1 | 0.9% | Dec 10, 2018 | Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicio... |
| CVE-2018-1279 | HIGH | 8.5 | 1.8% | Dec 10, 2018 | Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines wh... |
| CVE-2018-3988 | MEDIUM | 4.7 | 0.5% | Dec 10, 2018 | Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses th... |
| CVE-2018-1957 | MEDIUM | 4 | 0.4% | Dec 10, 2018 | IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by th... |
| CVE-2018-1671 | — | — | 1.7% | Dec 10, 2018 | IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML... |
| CVE-2018-1000866 | — | — | 1.6% | Dec 10, 2018 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/ko... |
| CVE-2018-1000865 | — | — | 1.6% | Dec 10, 2018 | A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/koh... |
| CVE-2018-1000864 | — | — | 2.8% | Dec 10, 2018 | A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allo... |
| CVE-2018-1000863 | — | — | 6.8% | Dec 10, 2018 | A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.... |
| CVE-2018-1000862 | — | — | 1.4% | Dec 10, 2018 | An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSu... |
| CVE-2018-1000861 | CRITICAL | 9.8 | 98.3% | Dec 10, 2018 | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea... |
| CVE-2018-20018 | — | — | 1.2% | Dec 10, 2018 | S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI. |
| CVE-2018-20017 | — | — | 0.6% | Dec 10, 2018 | SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI. |
| CVE-2018-20015 | — | — | 0.5% | Dec 10, 2018 | YzmCMS v5.2 has admin/role/add.html CSRF. |
| CVE-2018-20012 | — | — | 0.5% | Dec 10, 2018 | PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI. |
| CVE-2018-20011 | — | — | 4.4% | Dec 10, 2018 | DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. |
| CVE-2018-20010 | — | — | 4.4% | Dec 10, 2018 | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. |
| CVE-2018-20009 | — | — | 4.4% | Dec 10, 2018 | DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. |
| CVE-2018-20006 | — | — | 0.6% | Dec 10, 2018 | An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post... |
| CVE-2018-20005 | — | — | 1.1% | Dec 10, 2018 | An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonst... |
| CVE-2018-20004 | HIGH | 8.8 | 2.0% | Dec 10, 2018 | An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file... |
| CVE-2018-20002 | — | — | 1.8% | Dec 10, 2018 | The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distri... |
| CVE-2018-20001 | — | — | 1.0% | Dec 10, 2018 | In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits)... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now