2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-15854Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereferen...
CVE-2018-15853Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local atta...
CVE-2018-15852Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of ran...
CVE-2018-15851An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user...
CVE-2018-15850An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via ind...
CVE-2018-15849An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php.
CVE-2018-15848An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true.
CVE-2018-15847An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field...
CVE-2018-15846An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator'...
CVE-2018-15845There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
CVE-2018-15844An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas...
CVE-2018-15843GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
CVE-2018-15842WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
CVE-2018-15871An invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 20...
CVE-2018-15870An invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vul...
CVE-2018-15869An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and th...
CVE-2018-14059Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, ...
CVE-2018-15576An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited...
CVE-2018-11502An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t...
CVE-2018-15728Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authentic...
CVE-2018-15605An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacke...
CVE-2018-15536/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc...
CVE-2018-15535/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname ...
CVE-2018-15499GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condi...
CVE-2018-14600An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as sign...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now