2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19203 | — | — | 2.8% | Nov 12, 2018 | PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Servi... |
| CVE-2018-1884 | MEDIUM | 4.8 | 2.7% | Nov 12, 2018 | IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability wh... |
| CVE-2018-1798 | MEDIUM | 6.1 | 1.5% | Nov 12, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2018-1786 | MEDIUM | 5.3 | 2.4% | Nov 12, 2018 | IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. ... |
| CVE-2018-19200 | — | — | 2.5% | Nov 12, 2018 | An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetU... |
| CVE-2018-19199 | — | — | 2.3% | Nov 12, 2018 | An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriCo... |
| CVE-2018-19198 | — | — | 2.4% | Nov 12, 2018 | An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or ur... |
| CVE-2018-19197 | — | — | 1.4% | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. admin\controller\database.php allows arbitrary directory deletion via admin... |
| CVE-2018-19196 | — | — | 3.3% | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type para... |
| CVE-2018-19195 | — | — | 0.7% | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file. |
| CVE-2018-19194 | — | — | 0.9% | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to ope... |
| CVE-2018-19193 | — | — | 0.7% | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen. |
| CVE-2018-19192 | — | — | 0.5% | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by enteri... |
| CVE-2018-19185 | — | — | 2.1% | Nov 12, 2018 | An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/a... |
| CVE-2018-19184 | — | — | 1.5% | Nov 12, 2018 | cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted byte... |
| CVE-2018-19183 | HIGH | 7.5 | 3.1% | Nov 12, 2018 | ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.fr... |
| CVE-2018-18920 | — | — | 2.9% | Nov 12, 2018 | Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with ... |
| CVE-2018-19181 | — | — | 1.4% | Nov 11, 2018 | statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/c... |
| CVE-2018-19180 | — | — | 1.5% | Nov 11, 2018 | statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to ex... |
| CVE-2018-19178 | — | — | 0.6% | Nov 11, 2018 | In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED elemen... |
| CVE-2018-19170 | — | — | 0.6% | Nov 11, 2018 | In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/settin... |
| CVE-2018-19143 | — | — | 0.9% | Nov 11, 2018 | Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authentica... |
| CVE-2018-19142 | — | — | 0.5% | Nov 11, 2018 | Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL. |
| CVE-2018-19141 | — | — | 0.7% | Nov 11, 2018 | Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack v... |
| CVE-2018-19135 | — | — | 3.0% | Nov 11, 2018 | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now