2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17905 | — | — | 1.1% | Nov 5, 2018 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memo... |
| CVE-2018-18957 | — | — | 11.6% | Nov 5, 2018 | An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu... |
| CVE-2018-13397 | — | — | 2.1% | Nov 5, 2018 | There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Gi... |
| CVE-2018-13396 | — | — | 1.9% | Nov 5, 2018 | There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git su... |
| CVE-2018-18956 | — | — | 2.8% | Nov 5, 2018 | The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a den... |
| CVE-2018-18820 | — | — | 48.9% | Nov 5, 2018 | A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enable... |
| CVE-2018-9208 | — | — | 2.7% | Nov 5, 2018 | Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta |
| CVE-2018-18952 | — | — | 0.6% | Nov 5, 2018 | JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI. |
| CVE-2018-18950 | — | — | 2.1% | Nov 5, 2018 | KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directo... |
| CVE-2018-18949 | — | — | 24.5% | Nov 5, 2018 | Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. |
| CVE-2018-18943 | — | — | 0.7% | Nov 5, 2018 | An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category ... |
| CVE-2018-18942 | — | — | 2.4% | Nov 5, 2018 | In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the ... |
| CVE-2018-18939 | — | — | 0.7% | Nov 5, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field. |
| CVE-2018-18938 | — | — | 0.7% | Nov 5, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to... |
| CVE-2018-18937 | — | — | 1.7% | Nov 5, 2018 | An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_c... |
| CVE-2018-18936 | — | — | 2.5% | Nov 5, 2018 | An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via dir... |
| CVE-2018-18935 | — | — | 0.6% | Nov 5, 2018 | An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as dem... |
| CVE-2018-18934 | — | — | 0.8% | Nov 5, 2018 | An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component... |
| CVE-2018-18933 | — | — | 3.0% | Nov 5, 2018 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att... |
| CVE-2018-18928 | — | — | 2.9% | Nov 4, 2018 | International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toSc... |
| CVE-2018-18927 | — | — | 0.6% | Nov 4, 2018 | An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typicall... |
| CVE-2018-18926 | — | — | 3.0% | Nov 4, 2018 | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to se... |
| CVE-2018-18925 | — | — | 31.9% | Nov 4, 2018 | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." s... |
| CVE-2018-18924 | — | — | 9.5% | Nov 4, 2018 | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file... |
| CVE-2018-18919 | — | — | 0.8% | Nov 4, 2018 | The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now