2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16634 | — | — | 0.5% | Dec 4, 2018 | Pluck v4.7.7 allows CSRF via admin.php?action=settings. |
| CVE-2018-16633 | — | — | 0.6% | Dec 4, 2018 | Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. |
| CVE-2018-16631 | — | — | 0.6% | Dec 4, 2018 | Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. |
| CVE-2018-16629 | — | — | 0.6% | Dec 4, 2018 | panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. |
| CVE-2018-16628 | — | — | 0.6% | Dec 4, 2018 | panel/login in Kirby v2.5.12 allows XSS via a blog name. |
| CVE-2018-17159 | — | — | 4.2% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS r... |
| CVE-2018-17158 | — | — | 4.4% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client... |
| CVE-2018-17157 | — | — | 24.2% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause me... |
| CVE-2018-6982 | MEDIUM | 6.5 | 0.5% | Dec 4, 2018 | VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stac... |
| CVE-2018-6981 | HIGH | 8.8 | 1.3% | Dec 4, 2018 | VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without E... |
| CVE-2018-16478 | — | — | 1.3% | Dec 4, 2018 | A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. |
| CVE-2018-19853 | — | — | 0.9% | Dec 4, 2018 | An issue was discovered in hitshop through 2014-07-15. There is an elevation-of-privilege vulnerability (that allows con... |
| CVE-2018-19849 | — | — | 0.5% | Dec 4, 2018 | An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter. |
| CVE-2018-19843 | — | — | 1.0% | Dec 4, 2018 | opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read... |
| CVE-2018-19842 | — | — | 1.0% | Dec 4, 2018 | getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based b... |
| CVE-2018-19841 | MEDIUM | 5.5 | 2.5% | Dec 4, 2018 | The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause... |
| CVE-2018-19840 | — | — | 2.3% | Dec 4, 2018 | The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial... |
| CVE-2018-19839 | — | — | 2.2% | Dec 4, 2018 | In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service r... |
| CVE-2018-19838 | — | — | 1.9% | Dec 4, 2018 | In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow attackers to cause a den... |
| CVE-2018-19837 | — | — | 1.8% | Dec 4, 2018 | In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp allows attackers to cause a ... |
| CVE-2018-4021 | HIGH | 7.2 | 72.2% | Dec 3, 2018 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the paramete... |
| CVE-2018-4020 | HIGH | 7.2 | 48.7% | Dec 3, 2018 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the paramete... |
| CVE-2018-4019 | HIGH | 7.2 | 48.7% | Dec 3, 2018 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the paramete... |
| CVE-2018-3854 | HIGH | 7.1 | 0.4% | Dec 3, 2018 | An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 20... |
| CVE-2018-14709 | — | — | 1.9% | Dec 3, 2018 | Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass auth... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now