2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15880 | — | — | 1.0% | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a s... |
| CVE-2018-15121 | — | — | 0.5% | Aug 29, 2018 | An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state ... |
| CVE-2018-15897 | — | — | 1.1% | Aug 28, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript... |
| CVE-2018-15896 | — | — | 0.5% | Aug 28, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name. |
| CVE-2018-6643 | — | — | 0.8% | Aug 28, 2018 | Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter. |
| CVE-2018-15901 | — | — | 0.6% | Aug 28, 2018 | e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including admini... |
| CVE-2018-15884 | — | — | 2.5% | Aug 28, 2018 | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. |
| CVE-2018-15608 | — | — | 2.5% | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. |
| CVE-2018-15596 | — | — | 2.3% | Aug 28, 2018 | An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can gener... |
| CVE-2018-14572 | — | — | 2.4% | Aug 28, 2018 | In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a... |
| CVE-2018-14400 | — | — | — | Aug 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-15571 | — | — | 1.5% | Aug 28, 2018 | The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. |
| CVE-2018-15529 | — | — | 4.8% | Aug 28, 2018 | A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authentic... |
| CVE-2018-13395 | — | — | 1.0% | Aug 28, 2018 | Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 be... |
| CVE-2018-13391 | — | — | 1.8% | Aug 28, 2018 | The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v... |
| CVE-2018-15911 | — | — | 3.0% | Aug 28, 2018 | In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memor... |
| CVE-2018-3690 | — | — | — | Aug 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3693. Reason: This issue was MERGED into CVE-201... |
| CVE-2018-15910 | — | — | 3.0% | Aug 27, 2018 | In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the ... |
| CVE-2018-15909 | — | — | 3.0% | Aug 27, 2018 | In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers ab... |
| CVE-2018-15908 | — | — | 1.9% | Aug 27, 2018 | In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfi... |
| CVE-2018-15904 | — | — | 1.1% | Aug 27, 2018 | A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8,... |
| CVE-2018-15887 | — | — | 3.7% | Aug 27, 2018 | Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allo... |
| CVE-2018-15810 | — | — | 1.8% | Aug 27, 2018 | Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize f... |
| CVE-2018-15699 | — | — | 0.6% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in t... |
| CVE-2018-15698 | — | — | 1.1% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file sy... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now