2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19228 | — | — | 1.5% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic... |
| CVE-2018-19227 | — | — | 0.6% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter. |
| CVE-2018-19226 | — | — | 1.2% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /da... |
| CVE-2018-19225 | — | — | 0.5% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF. |
| CVE-2018-19224 | — | — | 1.0% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies. |
| CVE-2018-19223 | — | — | 0.6% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows XSS via the first input field to the admin/type.php?id=1 URI. |
| CVE-2018-19222 | — | — | 1.4% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin passwor... |
| CVE-2018-19221 | — | — | 1.2% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter. |
| CVE-2018-19220 | — | — | 1.7% | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host paramete... |
| CVE-2018-19219 | — | — | 1.1% | Nov 12, 2018 | In LibSass 3.5-stable, there is an illegal address access at Sass::Eval::operator that will lead to a DoS attack. |
| CVE-2018-19218 | — | — | 1.2% | Nov 12, 2018 | In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead... |
| CVE-2018-19217 | MEDIUM | 6.5 | 1.1% | Nov 12, 2018 | In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to... |
| CVE-2018-19216 | — | — | 1.3% | Nov 12, 2018 | Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c. |
| CVE-2018-19215 | — | — | 1.2% | Nov 12, 2018 | Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the speci... |
| CVE-2018-19214 | — | — | 1.3% | Nov 12, 2018 | Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insuffici... |
| CVE-2018-19213 | — | — | 0.8% | Nov 12, 2018 | Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/mallo... |
| CVE-2018-19212 | — | — | 0.9% | Nov 12, 2018 | In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS a... |
| CVE-2018-19211 | MEDIUM | 5.5 | 0.9% | Nov 12, 2018 | In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a den... |
| CVE-2018-19210 | — | — | 3.6% | Nov 12, 2018 | In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will ... |
| CVE-2018-19209 | — | — | 0.8% | Nov 12, 2018 | Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will le... |
| CVE-2018-19208 | MEDIUM | 6.5 | 1.5% | Nov 12, 2018 | In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListe... |
| CVE-2018-19207 | — | — | 87.3% | Nov 12, 2018 | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe... |
| CVE-2018-19206 | — | — | 60.2% | Nov 12, 2018 | steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attr... |
| CVE-2018-19205 | — | — | 1.6% | Nov 12, 2018 | Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain... |
| CVE-2018-19204 | — | — | 4.6% | Nov 12, 2018 | PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now