2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14798 | — | — | 1.3% | Oct 1, 2018 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA,... |
| CVE-2018-14794 | — | — | 1.9% | Oct 1, 2018 | Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a pr... |
| CVE-2018-14790 | — | — | 5.4% | Oct 1, 2018 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA,... |
| CVE-2018-14788 | — | — | 1.4% | Oct 1, 2018 | Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. A buffer overflow information disclosure vulnerability occurs ... |
| CVE-2018-17854 | — | — | 1.5% | Oct 1, 2018 | SIMDComp before 0.1.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application ... |
| CVE-2018-17852 | — | — | 1.5% | Oct 1, 2018 | A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to ... |
| CVE-2018-17851 | — | — | — | Oct 1, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-17850 | — | — | — | Oct 1, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-17838 | — | — | 1.5% | Oct 1, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/... |
| CVE-2018-17837 | — | — | 1.3% | Oct 1, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=ac... |
| CVE-2018-17836 | — | — | 1.6% | Oct 1, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /conso... |
| CVE-2018-17835 | — | — | 0.7% | Oct 1, 2018 | An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custo... |
| CVE-2018-17832 | — | — | 2.3% | Oct 1, 2018 | XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. |
| CVE-2018-17831 | — | — | 2.1% | Oct 1, 2018 | In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the ... |
| CVE-2018-17830 | — | — | 0.7% | Oct 1, 2018 | The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are no... |
| CVE-2018-17828 | — | — | 1.5% | Oct 1, 2018 | Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in... |
| CVE-2018-17827 | — | — | 1.4% | Oct 1, 2018 | HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. Thi... |
| CVE-2018-17826 | — | — | 0.5% | Oct 1, 2018 | HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then u... |
| CVE-2018-17427 | — | — | 1.5% | Oct 1, 2018 | SIMDComp before 0.1.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application ... |
| CVE-2018-17217 | — | — | 0.8% | Oct 1, 2018 | An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key. |
| CVE-2018-17216 | — | — | 1.1% | Oct 1, 2018 | An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users. |
| CVE-2018-17798 | — | — | 1.2% | Sep 30, 2018 | An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolut... |
| CVE-2018-17797 | — | — | 1.4% | Sep 30, 2018 | An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory tr... |
| CVE-2018-17796 | — | — | 1.5% | Sep 30, 2018 | An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T param... |
| CVE-2018-17795 | — | — | 4.1% | Sep 30, 2018 | The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of servi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now