2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14503 | — | — | 0.8% | Aug 10, 2018 | Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbit... |
| CVE-2018-14028 | — | — | 17.7% | Aug 10, 2018 | In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files t... |
| CVE-2018-11492 | — | — | 11.4% | Aug 10, 2018 | ASUS HG100 devices allow denial of service via an IPv4 packet flood. |
| CVE-2018-6556 | — | — | 0.3% | Aug 10, 2018 | lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may... |
| CVE-2018-6553 | — | — | 0.4% | Aug 10, 2018 | The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possib... |
| CVE-2018-15189 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile. |
| CVE-2018-15188 | — | — | 0.9% | Aug 10, 2018 | PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure ... |
| CVE-2018-15187 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. |
| CVE-2018-15186 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. |
| CVE-2018-15185 | — | — | 0.9% | Aug 10, 2018 | PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page ... |
| CVE-2018-13390 | — | — | 0.5% | Aug 10, 2018 | Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attacke... |
| CVE-2018-10769 | — | — | 0.9% | Aug 10, 2018 | The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 t... |
| CVE-2018-7692 | — | — | 0.6% | Aug 9, 2018 | Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. |
| CVE-2018-7686 | — | — | 1.4% | Aug 9, 2018 | Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. |
| CVE-2018-14735 | — | — | 1.4% | Aug 9, 2018 | An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a ... |
| CVE-2018-0429 | — | — | 0.5% | Aug 9, 2018 | Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows loca... |
| CVE-2018-15184 | — | — | 0.5% | Aug 9, 2018 | PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to C... |
| CVE-2018-15183 | — | — | 0.7% | Aug 9, 2018 | PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields... |
| CVE-2018-15182 | — | — | 0.5% | Aug 9, 2018 | PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields. |
| CVE-2018-15181 | — | — | 5.3% | Aug 9, 2018 | JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo... |
| CVE-2018-6922 | — | — | 3.2% | Aug 9, 2018 | One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12... |
| CVE-2018-14526 | — | — | 1.4% | Aug 8, 2018 | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of ... |
| CVE-2018-11769 | — | — | 8.2% | Aug 8, 2018 | CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation ... |
| CVE-2018-15209 | — | — | 4.0% | Aug 8, 2018 | ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (he... |
| CVE-2018-15202 | — | — | 0.4% | Aug 8, 2018 | An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/temp... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now