2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16324In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
CVE-2018-16320idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code f...
CVE-2018-16316A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to injec...
CVE-2018-16315In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=a...
CVE-2018-16314An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exis...
CVE-2018-16313Bludit 2.3.4 allows XSS via a user name.
CVE-2018-16308The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
CVE-2018-16303PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a c...
CVE-2018-16302MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
CVE-2018-15161The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause ...
CVE-2018-15160The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows rem...
CVE-2018-15159The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause ...
CVE-2018-15158The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to caus...
CVE-2018-15157The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a...
CVE-2018-15514HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deseria...
CVE-2018-16298An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=...
CVE-2018-6259NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an...
CVE-2018-6258NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation...
CVE-2018-6257NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled whe...
CVE-2018-16278phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the ...
CVE-2018-16275OPSWAT MetaDefender before v4.11.2 allows CSV injection.
CVE-2018-16239An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to ...
CVE-2018-16238An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to...
CVE-2018-16237An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.p...
CVE-2018-16236cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now