2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15854 | — | — | 0.4% | Aug 25, 2018 | Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereferen... |
| CVE-2018-15853 | — | — | 0.5% | Aug 25, 2018 | Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local atta... |
| CVE-2018-15852 | — | — | 1.1% | Aug 25, 2018 | Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of ran... |
| CVE-2018-15851 | — | — | 0.6% | Aug 25, 2018 | An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user... |
| CVE-2018-15850 | — | — | 0.6% | Aug 25, 2018 | An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via ind... |
| CVE-2018-15849 | — | — | 0.4% | Aug 25, 2018 | An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php. |
| CVE-2018-15848 | — | — | 0.5% | Aug 25, 2018 | An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true. |
| CVE-2018-15847 | — | — | 0.9% | Aug 25, 2018 | An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field... |
| CVE-2018-15846 | — | — | 0.7% | Aug 25, 2018 | An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator'... |
| CVE-2018-15845 | — | — | 2.3% | Aug 25, 2018 | There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. |
| CVE-2018-15844 | — | — | 2.5% | Aug 25, 2018 | An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas... |
| CVE-2018-15843 | — | — | 0.6% | Aug 25, 2018 | GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field. |
| CVE-2018-15842 | — | — | 0.7% | Aug 25, 2018 | WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter. |
| CVE-2018-15871 | — | — | 1.2% | Aug 25, 2018 | An invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 20... |
| CVE-2018-15870 | — | — | 1.2% | Aug 25, 2018 | An invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vul... |
| CVE-2018-15869 | — | — | 1.8% | Aug 25, 2018 | An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and th... |
| CVE-2018-14059 | — | — | 3.1% | Aug 24, 2018 | Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, ... |
| CVE-2018-15576 | — | — | 9.7% | Aug 24, 2018 | An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited... |
| CVE-2018-11502 | — | — | 1.9% | Aug 24, 2018 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t... |
| CVE-2018-15728 | — | — | 2.9% | Aug 24, 2018 | Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authentic... |
| CVE-2018-15605 | — | — | 1.7% | Aug 24, 2018 | An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacke... |
| CVE-2018-15536 | — | — | 6.4% | Aug 24, 2018 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc... |
| CVE-2018-15535 | — | — | 45.2% | Aug 24, 2018 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname ... |
| CVE-2018-15499 | — | — | 0.4% | Aug 24, 2018 | GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condi... |
| CVE-2018-14600 | — | — | 9.7% | Aug 24, 2018 | An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as sign... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now