2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1002006 | — | — | 2.6% | Dec 3, 2018 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact... |
| CVE-2018-1002005 | — | — | 3.1% | Dec 3, 2018 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4... |
| CVE-2018-1002004 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002003 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002002 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002001 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002000 | — | — | 4.4% | Dec 3, 2018 | There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad... |
| CVE-2018-7116 | — | — | 10.3% | Dec 3, 2018 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via... |
| CVE-2018-7115 | — | — | 13.4% | Dec 3, 2018 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in db... |
| CVE-2018-7114 | — | — | 32.8% | Dec 3, 2018 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbma... |
| CVE-2018-7113 | — | — | 0.7% | Dec 3, 2018 | A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the ... |
| CVE-2018-7112 | — | — | 0.7% | Dec 3, 2018 | The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of pri... |
| CVE-2018-1840 | MEDIUM | 6 | 2.1% | Dec 3, 2018 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, ca... |
| CVE-2018-6332 | MEDIUM | 5.9 | 1.1% | Dec 3, 2018 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spe... |
| CVE-2018-16869 | MEDIUM | 5.7 | 1.5% | Dec 3, 2018 | A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of ... |
| CVE-2018-16868 | MEDIUM | 5.6 | 0.6% | Dec 3, 2018 | A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA d... |
| CVE-2018-16855 | HIGH | 7.5 | 59.5% | Dec 3, 2018 | An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigge... |
| CVE-2018-19797 | — | — | 1.8% | Dec 3, 2018 | In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (use... |
| CVE-2018-19796 | — | — | 1.6% | Dec 3, 2018 | An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via ... |
| CVE-2018-19795 | — | — | 0.4% | Dec 3, 2018 | ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full a... |
| CVE-2018-19794 | — | — | 1.1% | Dec 3, 2018 | Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to... |
| CVE-2018-19793 | — | — | 2.4% | Dec 3, 2018 | jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 ... |
| CVE-2018-19792 | — | — | 0.4% | Dec 3, 2018 | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow)... |
| CVE-2018-19791 | — | — | 1.2% | Dec 3, 2018 | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing a... |
| CVE-2018-19788 | — | — | 11.5% | Dec 3, 2018 | A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully exec... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now