2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19468 | — | — | 1.1% | Nov 23, 2018 | HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the u... |
| CVE-2018-19464 | MEDIUM | 4.8 | 0.5% | Nov 22, 2018 | Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishand... |
| CVE-2018-19463 | — | — | 2.2% | Nov 22, 2018 | zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by us... |
| CVE-2018-19459 | — | — | 4.0% | Nov 22, 2018 | Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file. |
| CVE-2018-19458 | — | — | 32.9% | Nov 22, 2018 | In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR... |
| CVE-2018-19457 | — | — | 3.9% | Nov 22, 2018 | Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faq... |
| CVE-2018-19443 | — | — | 0.9% | Nov 22, 2018 | The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under cert... |
| CVE-2018-19437 | — | — | 1.1% | Nov 22, 2018 | UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] ... |
| CVE-2018-19436 | — | — | 1.1% | Nov 22, 2018 | An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injecti... |
| CVE-2018-19435 | — | — | 1.1% | Nov 22, 2018 | An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy paramet... |
| CVE-2018-19434 | — | — | 1.1% | Nov 22, 2018 | An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15.... |
| CVE-2018-19433 | — | — | 0.9% | Nov 22, 2018 | ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value. |
| CVE-2018-19432 | — | — | 3.0% | Nov 22, 2018 | An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfil... |
| CVE-2018-19424 | — | — | 1.8% | Nov 21, 2018 | ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files. |
| CVE-2018-19423 | HIGH | 7.2 | 18.0% | Nov 21, 2018 | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. |
| CVE-2018-19422 | HIGH | 7.2 | 65.1% | Nov 21, 2018 | /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca... |
| CVE-2018-19421 | — | — | 0.8% | Nov 21, 2018 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file,... |
| CVE-2018-19420 | — | — | 0.8% | Nov 21, 2018 | In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can ... |
| CVE-2018-19417 | — | — | 5.7% | Nov 21, 2018 | An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT ... |
| CVE-2018-19416 | — | — | 1.7% | Nov 21, 2018 | An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a m... |
| CVE-2018-19411 | — | — | 0.9% | Nov 21, 2018 | PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user wi... |
| CVE-2018-19410 | CRITICAL | 9.8 | 85.7% | Nov 21, 2018 | PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile... |
| CVE-2018-19409 | — | — | 7.8% | Nov 21, 2018 | An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device ... |
| CVE-2018-1843 | MEDIUM | 4.1 | 0.3% | Nov 21, 2018 | The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to... |
| CVE-2018-19407 | — | — | 0.5% | Nov 21, 2018 | The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a den... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now