2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-17905When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memo...
CVE-2018-18957An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu...
CVE-2018-13397There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Gi...
CVE-2018-13396There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git su...
CVE-2018-18956The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a den...
CVE-2018-18820A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enable...
CVE-2018-9208Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta
CVE-2018-18952JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
CVE-2018-18950KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directo...
CVE-2018-18949Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
CVE-2018-18943An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category ...
CVE-2018-18942In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the ...
CVE-2018-18939An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
CVE-2018-18938An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to...
CVE-2018-18937An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_c...
CVE-2018-18936An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via dir...
CVE-2018-18935An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as dem...
CVE-2018-18934An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component...
CVE-2018-18933The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att...
CVE-2018-18928International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toSc...
CVE-2018-18927An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typicall...
CVE-2018-18926Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to se...
CVE-2018-18925Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." s...
CVE-2018-18924The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file...
CVE-2018-18919The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now