2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16353An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit par...
CVE-2018-16352There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a ....
CVE-2018-16350WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
CVE-2018-16349WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
CVE-2018-16348SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
CVE-2018-16347An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
CVE-2018-16346ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
CVE-2018-16345An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s...
CVE-2018-16344An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal seque...
CVE-2018-16343SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block...
CVE-2018-16342ShowDoc v1.8.0 has XSS via a new page.
CVE-2018-16339An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/u...
CVE-2018-16338An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via a...
CVE-2018-16337An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration v...
CVE-2018-16336Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based...
CVE-2018-16335newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause ...
CVE-2018-16334An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST...
CVE-2018-16333An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19...
CVE-2018-16332An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
CVE-2018-16331admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
CVE-2018-16330Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
CVE-2018-16329In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/propert...
CVE-2018-16328In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
CVE-2018-16327There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
CVE-2018-16325There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now