2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19468HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the u...
CVE-2018-19464MEDIUM4.8Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishand...
CVE-2018-19463zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by us...
CVE-2018-19459Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.
CVE-2018-19458In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR...
CVE-2018-19457Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faq...
CVE-2018-19443The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under cert...
CVE-2018-19437UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] ...
CVE-2018-19436An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injecti...
CVE-2018-19435An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy paramet...
CVE-2018-19434An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15....
CVE-2018-19433ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
CVE-2018-19432An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfil...
CVE-2018-19424ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.
CVE-2018-19423HIGH7.2Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
CVE-2018-19422HIGH7.2/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca...
CVE-2018-19421In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file,...
CVE-2018-19420In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can ...
CVE-2018-19417An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT ...
CVE-2018-19416An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a m...
CVE-2018-19411PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user wi...
CVE-2018-19410CRITICAL9.8PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile...
CVE-2018-19409An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device ...
CVE-2018-1843MEDIUM4.1The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to...
CVE-2018-19407The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a den...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now