2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-25095CRITICAL9.8The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values i...
CVE-2018-25093CRITICAL9.8A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this iss...
CVE-2018-25092CRITICAL9.8A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this ...
CVE-2018-17879CRITICAL9.8An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system(...
CVE-2018-17878CRITICAL9.8Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted s...
CVE-2018-17558CRITICAL9.8Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP...
CVE-2018-25088CRITICAL9.8A vulnerability, which was classified as critical, was found in Blue Yonder postgraas_server up to 2.0.0b2. Affected is ...
CVE-2018-17452CRITICAL9.8An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x befor...
CVE-2018-25083CRITICAL9.8The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git...
CVE-2018-25082CRITICAL9.8A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function ...
CVE-2018-25076CRITICAL9.8A vulnerability classified as critical was found in Events Extension on BigTree. Affected by this vulnerability is the f...
CVE-2018-25075CRITICAL9.8A vulnerability classified as critical has been found in karsany OBridge up to 1.3. Affected is the function getAllStand...
CVE-2018-25072CRITICAL9.8A vulnerability classified as critical has been found in lojban jbovlaste. This affects an unknown part of the file dict...
CVE-2018-25071CRITICAL9.8A vulnerability was found in roxlukas LMeve up to 0.1.58. It has been rated as critical. Affected by this issue is the f...
CVE-2018-25070CRITICAL9.8A vulnerability has been found in polterguy Phosphorus Five up to 8.2 and classified as critical. This vulnerability aff...
CVE-2018-25069CRITICAL9.8A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipul...
CVE-2018-25068CRITICAL9.8A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affe...
CVE-2018-25066CRITICAL9.8A vulnerability was found in PeterMu nodebatis up to 2.1.x. It has been classified as critical. Affected is an unknown f...
CVE-2018-25057CRITICAL9.8A vulnerability was found in simple_php_link_shortener. It has been classified as critical. Affected is an unknown funct...
CVE-2018-25046CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2018-18447CRITICAL9.8dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
CVE-2018-18446CRITICAL9.8dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
CVE-2018-25026CRITICAL9.8An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object tha...
CVE-2018-25025CRITICAL9.8An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string,...
CVE-2018-25024CRITICAL9.8An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference in...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now