2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16608 | — | — | 1.2% | Sep 10, 2018 | In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/ind... |
| CVE-2018-15886 | — | — | 1.6% | Sep 10, 2018 | Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippet... |
| CVE-2018-16790 | — | — | 2.1% | Sep 10, 2018 | _bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a h... |
| CVE-2018-16782 | — | — | 1.4% | Sep 10, 2018 | libimageworsener.a in ImageWorsener 1.3.2 has a buffer overflow in the bmpr_read_rle_internal function in imagew-bmp.c. |
| CVE-2018-16781 | — | — | 1.0% | Sep 10, 2018 | ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressi... |
| CVE-2018-16780 | — | — | 0.5% | Sep 10, 2018 | Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment. |
| CVE-2018-16779 | — | — | 0.7% | Sep 10, 2018 | BlogCMS through 2016-10-25 has XSS via a comment. |
| CVE-2018-16776 | — | — | 0.7% | Sep 10, 2018 | wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page. |
| CVE-2018-16775 | — | — | 0.5% | Sep 10, 2018 | An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu. |
| CVE-2018-16774 | — | — | 1.6% | Sep 10, 2018 | HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=del... |
| CVE-2018-16773 | — | — | 0.5% | Sep 10, 2018 | EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content fi... |
| CVE-2018-16772 | — | — | 0.7% | Sep 10, 2018 | Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new. |
| CVE-2018-16771 | — | — | 2.7% | Sep 10, 2018 | Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php. |
| CVE-2018-16770 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16769 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16768 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16767 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16766 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16765 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16764 | — | — | 1.3% | Sep 10, 2018 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (applic... |
| CVE-2018-16762 | — | — | 1.4% | Sep 9, 2018 | FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items. |
| CVE-2018-16761 | — | — | 2.2% | Sep 9, 2018 | Eventum before 3.4.0 has an open redirect vulnerability. |
| CVE-2018-16759 | — | — | 0.7% | Sep 9, 2018 | The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS... |
| CVE-2018-16736 | — | — | 2.6% | Sep 9, 2018 | In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec... |
| CVE-2018-16733 | — | — | 1.2% | Sep 8, 2018 | In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now