2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16456 | — | — | 0.7% | Oct 4, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has ... |
| CVE-2018-16453 | — | — | 0.7% | Oct 4, 2018 | PHP Scripts Mall Domain Lookup Script 3.0.5 allows XSS in the search bar. |
| CVE-2018-16326 | — | — | 0.7% | Oct 4, 2018 | PHP Scripts Mall Olx Clone 3.4.2 has XSS. |
| CVE-2018-13258 | — | — | 2.1% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that should... |
| CVE-2018-0505 | — | — | 1.9% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's acco... |
| CVE-2018-0504 | — | — | 2.8% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/... |
| CVE-2018-0503 | — | — | 1.5% | Oct 4, 2018 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimi... |
| CVE-2018-17876 | — | — | 1.0% | Oct 4, 2018 | A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product. |
| CVE-2018-17872 | — | — | 2.2% | Oct 4, 2018 | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions. |
| CVE-2018-5492 | — | — | 2.9% | Oct 4, 2018 | NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remo... |
| CVE-2018-11784 | — | — | 94.5% | Oct 4, 2018 | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r... |
| CVE-2018-17974 | — | — | 1.0% | Oct 3, 2018 | An issue was discovered in Tcpreplay 4.3.0 beta1. A heap-based buffer over-read was triggered in the function dlt_en10mb... |
| CVE-2018-17972 | — | — | 0.4% | Oct 3, 2018 | An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does no... |
| CVE-2018-5921 | — | — | 0.7% | Oct 3, 2018 | A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other fir... |
| CVE-2018-17881 | — | — | 1.5% | Oct 3, 2018 | On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authen... |
| CVE-2018-17880 | — | — | 1.6% | Oct 3, 2018 | On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication... |
| CVE-2018-17562 | — | — | 1.5% | Oct 3, 2018 | Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract ... |
| CVE-2018-17553 | — | — | 79.0% | Oct 3, 2018 | An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N... |
| CVE-2018-17552 | — | — | 84.1% | Oct 3, 2018 | SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat... |
| CVE-2018-17540 | — | — | 3.5% | Oct 3, 2018 | The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. |
| CVE-2018-17428 | — | — | 2.8% | Oct 3, 2018 | An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par... |
| CVE-2018-17408 | — | — | 19.0% | Oct 3, 2018 | Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a... |
| CVE-2018-17969 | — | — | 1.4% | Oct 3, 2018 | Samsung SCX-6545X V2.00.03.01 03-23-2012 devices allows remote attackers to discover cleartext credentials via iso.3.6.1... |
| CVE-2018-17967 | — | — | 1.5% | Oct 3, 2018 | ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c. |
| CVE-2018-17966 | — | — | 1.7% | Oct 3, 2018 | ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now