2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14646 | MEDIUM | 5.5 | 0.4% | Nov 26, 2018 | The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capabl... |
| CVE-2018-19564 | — | — | 0.9% | Nov 26, 2018 | Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_c... |
| CVE-2018-16854 | MEDIUM | 6.5 | 2.3% | Nov 26, 2018 | A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form ... |
| CVE-2018-1905 | HIGH | 7.1 | 2.5% | Nov 26, 2018 | IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack w... |
| CVE-2018-19562 | — | — | 2.2% | Nov 26, 2018 | An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code v... |
| CVE-2018-19561 | — | — | 0.4% | Nov 26, 2018 | sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account. |
| CVE-2018-19560 | — | — | 0.7% | Nov 26, 2018 | BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. |
| CVE-2018-19559 | — | — | 1.0% | Nov 26, 2018 | CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter. |
| CVE-2018-19558 | — | — | 1.1% | Nov 26, 2018 | An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because ... |
| CVE-2018-19557 | — | — | 1.5% | Nov 26, 2018 | An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/... |
| CVE-2018-19556 | — | — | 1.0% | Nov 26, 2018 | zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the... |
| CVE-2018-19555 | — | — | 0.5% | Nov 26, 2018 | tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password. |
| CVE-2018-19554 | — | — | 0.6% | Nov 26, 2018 | An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldNa... |
| CVE-2018-19553 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php |
| CVE-2018-19552 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. |
| CVE-2018-19551 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags... |
| CVE-2018-19550 | — | — | 6.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit ... |
| CVE-2018-19549 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php. |
| CVE-2018-19548 | — | — | 1.7% | Nov 26, 2018 | index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm... |
| CVE-2018-19547 | — | — | 0.7% | Nov 26, 2018 | JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter. |
| CVE-2018-19546 | — | — | 0.5% | Nov 26, 2018 | JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload... |
| CVE-2018-19545 | — | — | 0.5% | Nov 26, 2018 | JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. |
| CVE-2018-19544 | — | — | 0.4% | Nov 26, 2018 | JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. |
| CVE-2018-19543 | — | — | 1.6% | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in... |
| CVE-2018-19542 | — | — | 1.9% | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now