2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16324 | — | — | 1.1% | Sep 1, 2018 | In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. |
| CVE-2018-16320 | — | — | 2.4% | Sep 1, 2018 | idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code f... |
| CVE-2018-16316 | — | — | 0.8% | Sep 1, 2018 | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to injec... |
| CVE-2018-16315 | — | — | 0.4% | Sep 1, 2018 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=a... |
| CVE-2018-16314 | — | — | 0.7% | Sep 1, 2018 | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exis... |
| CVE-2018-16313 | — | — | 0.7% | Sep 1, 2018 | Bludit 2.3.4 allows XSS via a user name. |
| CVE-2018-16308 | — | — | 1.8% | Sep 1, 2018 | The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. |
| CVE-2018-16303 | — | — | 1.6% | Sep 1, 2018 | PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a c... |
| CVE-2018-16302 | — | — | 4.3% | Sep 1, 2018 | MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file. |
| CVE-2018-15161 | — | — | 1.5% | Sep 1, 2018 | The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause ... |
| CVE-2018-15160 | — | — | 1.5% | Sep 1, 2018 | The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows rem... |
| CVE-2018-15159 | — | — | 1.5% | Sep 1, 2018 | The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause ... |
| CVE-2018-15158 | — | — | 1.5% | Sep 1, 2018 | The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to caus... |
| CVE-2018-15157 | — | — | 1.5% | Sep 1, 2018 | The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a... |
| CVE-2018-15514 | — | — | 2.5% | Sep 1, 2018 | HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deseria... |
| CVE-2018-16298 | — | — | 0.9% | Aug 31, 2018 | An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=... |
| CVE-2018-6259 | — | — | 0.2% | Aug 31, 2018 | NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an... |
| CVE-2018-6258 | — | — | 0.3% | Aug 31, 2018 | NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation... |
| CVE-2018-6257 | — | — | 0.3% | Aug 31, 2018 | NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled whe... |
| CVE-2018-16278 | — | — | 1.6% | Aug 31, 2018 | phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the ... |
| CVE-2018-16275 | — | — | 0.9% | Aug 31, 2018 | OPSWAT MetaDefender before v4.11.2 allows CSV injection. |
| CVE-2018-16239 | — | — | 1.2% | Aug 30, 2018 | An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to ... |
| CVE-2018-16238 | — | — | 2.2% | Aug 30, 2018 | An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to... |
| CVE-2018-16237 | — | — | 1.2% | Aug 30, 2018 | An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.p... |
| CVE-2018-16236 | — | — | 0.7% | Aug 30, 2018 | cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now