2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17092 | — | — | 0.6% | Sep 16, 2018 | An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be explo... |
| CVE-2018-17091 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via ... |
| CVE-2018-17090 | — | — | 0.5% | Sep 16, 2018 | An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulne... |
| CVE-2018-17088 | — | — | 1.6% | Sep 16, 2018 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service... |
| CVE-2018-17086 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 t... |
| CVE-2018-17085 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeS... |
| CVE-2018-17062 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isuni... |
| CVE-2018-17082 | — | — | 4.1% | Sep 16, 2018 | The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS... |
| CVE-2018-17077 | — | — | 0.8% | Sep 16, 2018 | An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be ... |
| CVE-2018-17076 | — | — | 1.5% | Sep 16, 2018 | GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or po... |
| CVE-2018-17074 | — | — | 1.2% | Sep 16, 2018 | The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. |
| CVE-2018-17073 | — | — | 1.2% | Sep 16, 2018 | wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image. |
| CVE-2018-17072 | — | — | 1.6% | Sep 16, 2018 | JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y. |
| CVE-2018-16554 | — | — | 1.8% | Sep 16, 2018 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service... |
| CVE-2018-17070 | — | — | 0.5% | Sep 15, 2018 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2F... |
| CVE-2018-17069 | — | — | 0.5% | Sep 15, 2018 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay... |
| CVE-2018-17068 | — | — | 3.7% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17067 | — | — | 1.9% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a... |
| CVE-2018-17066 | — | — | 7.3% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17065 | — | — | 1.9% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a ... |
| CVE-2018-17064 | — | — | 7.4% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17063 | — | — | 4.1% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17061 | — | — | 0.7% | Sep 15, 2018 | BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search res... |
| CVE-2018-16706 | — | — | 22.3% | Sep 14, 2018 | LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/devi... |
| CVE-2018-16288 | — | — | 35.3% | Sep 14, 2018 | LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now