2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17134 | — | — | 1.8% | Sep 17, 2018 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjuncti... |
| CVE-2018-17133 | — | — | 1.8% | Sep 17, 2018 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. |
| CVE-2018-17132 | — | — | 1.8% | Sep 17, 2018 | admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter... |
| CVE-2018-17131 | — | — | 1.8% | Sep 17, 2018 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. |
| CVE-2018-17130 | — | — | 0.5% | Sep 17, 2018 | PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, |
| CVE-2018-17129 | — | — | 0.9% | Sep 17, 2018 | MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field... |
| CVE-2018-17128 | — | — | 74.8% | Sep 17, 2018 | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. |
| CVE-2018-17127 | — | — | 1.5% | Sep 17, 2018 | blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of se... |
| CVE-2018-17126 | — | — | 3.2% | Sep 17, 2018 | CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Ins... |
| CVE-2018-17125 | — | — | 1.4% | Sep 17, 2018 | CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php. |
| CVE-2018-17113 | — | — | 0.6% | Sep 17, 2018 | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or m... |
| CVE-2018-17110 | — | — | 1.6% | Sep 17, 2018 | Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the managemen... |
| CVE-2018-16309 | — | — | — | Sep 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-17108 | — | — | 1.1% | Sep 16, 2018 | The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeove... |
| CVE-2018-17106 | — | — | 0.9% | Sep 16, 2018 | In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An... |
| CVE-2018-17104 | — | — | 0.8% | Sep 16, 2018 | An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrat... |
| CVE-2018-17103 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's pass... |
| CVE-2018-17102 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrat... |
| CVE-2018-17101 | — | — | 3.2% | Sep 16, 2018 | An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2... |
| CVE-2018-17100 | — | — | 2.5% | Sep 16, 2018 | An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause ... |
| CVE-2018-17098 | — | — | 2.8% | Sep 16, 2018 | The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of serv... |
| CVE-2018-17097 | — | — | 2.8% | Sep 16, 2018 | The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of serv... |
| CVE-2018-17096 | — | — | 2.3% | Sep 16, 2018 | The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cau... |
| CVE-2018-17094 | — | — | — | Sep 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11124. Reason: This candidate is a duplicate of ... |
| CVE-2018-17093 | — | — | — | Sep 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11125. Reason: This candidate is a duplicate of ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now