2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17366 | — | — | 0.6% | Sep 23, 2018 | An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/... |
| CVE-2018-17364 | — | — | 0.9% | Sep 23, 2018 | OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. |
| CVE-2018-17361 | — | — | 0.8% | Sep 23, 2018 | Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the P... |
| CVE-2018-17360 | — | — | 1.3% | Sep 23, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a... |
| CVE-2018-17359 | — | — | 1.2% | Sep 23, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. A... |
| CVE-2018-17358 | — | — | 1.3% | Sep 23, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. A... |
| CVE-2018-17341 | — | — | 1.9% | Sep 23, 2018 | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authent... |
| CVE-2018-17338 | — | — | 1.2% | Sep 23, 2018 | An issue has been found in pdfalto through 0.2. It is a heap-based buffer overflow in the function TextPage::dump in Xml... |
| CVE-2018-17336 | — | — | 0.6% | Sep 22, 2018 | UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive ... |
| CVE-2018-17334 | — | — | 1.6% | Sep 22, 2018 | An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function... |
| CVE-2018-17333 | — | — | 1.6% | Sep 22, 2018 | An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c... |
| CVE-2018-17332 | — | — | 1.2% | Sep 22, 2018 | An issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its inpu... |
| CVE-2018-17322 | — | — | 0.8% | Sep 22, 2018 | Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to i... |
| CVE-2018-17321 | — | — | 0.7% | Sep 22, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorando... |
| CVE-2018-14891 | — | — | 0.3% | Sep 21, 2018 | Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerab... |
| CVE-2018-14890 | — | — | 0.5% | Sep 21, 2018 | Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Manag... |
| CVE-2018-14889 | — | — | 0.6% | Sep 21, 2018 | CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. |
| CVE-2018-12169 | — | — | 0.6% | Sep 21, 2018 | Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generatio... |
| CVE-2018-17320 | — | — | 0.7% | Sep 21, 2018 | An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin... |
| CVE-2018-17317 | — | — | 4.3% | Sep 21, 2018 | FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharac... |
| CVE-2018-17174 | — | — | 2.6% | Sep 21, 2018 | A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c al... |
| CVE-2018-17173 | — | — | 56.2% | Sep 21, 2018 | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT... |
| CVE-2018-17141 | — | — | 5.6% | Sep 21, 2018 | HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a ... |
| CVE-2018-17050 | — | — | 0.9% | Sep 21, 2018 | The mintToken function of a smart contract implementation for PolyAi (AI), an Ethereum token, has an integer overflow th... |
| CVE-2018-17003 | — | — | 1.0% | Sep 21, 2018 | In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title paramete... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now