2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15199 | — | — | 0.6% | Aug 8, 2018 | AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action. |
| CVE-2018-15198 | — | — | 0.7% | Aug 8, 2018 | An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a use... |
| CVE-2018-15197 | — | — | 0.7% | Aug 8, 2018 | An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that... |
| CVE-2018-15193 | — | — | 0.8% | Aug 8, 2018 | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via ... |
| CVE-2018-15192 | — | — | 2.1% | Aug 8, 2018 | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access ... |
| CVE-2018-15178 | — | — | 1.3% | Aug 8, 2018 | Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and cond... |
| CVE-2018-15177 | — | — | 0.6% | Aug 8, 2018 | In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. |
| CVE-2018-15176 | — | — | 1.0% | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x00000... |
| CVE-2018-15175 | — | — | 1.0% | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVar... |
| CVE-2018-15174 | — | — | 1.0% | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and a... |
| CVE-2018-15173 | — | — | 6.1% | Aug 8, 2018 | Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption ... |
| CVE-2018-15169 | — | — | 1.7% | Aug 8, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 all... |
| CVE-2018-15168 | — | — | 3.9% | Aug 8, 2018 | A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids ... |
| CVE-2018-15137 | — | — | 18.2% | Aug 8, 2018 | CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)... |
| CVE-2018-5995 | — | — | 0.4% | Aug 7, 2018 | The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sens... |
| CVE-2018-15132 | — | — | 4.6% | Aug 7, 2018 | An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and... |
| CVE-2018-12885 | — | — | 1.4% | Aug 7, 2018 | The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random valu... |
| CVE-2018-11456 | — | — | 1.3% | Aug 7, 2018 | A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network a... |
| CVE-2018-11455 | — | — | 5.3% | Aug 7, 2018 | A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager... |
| CVE-2018-11454 | — | — | 0.4% | Aug 7, 2018 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), ... |
| CVE-2018-11453 | — | — | 0.4% | Aug 7, 2018 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), ... |
| CVE-2018-15130 | — | — | 0.7% | Aug 7, 2018 | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter. |
| CVE-2018-15129 | — | — | 0.7% | Aug 7, 2018 | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter. |
| CVE-2018-14869 | — | — | 1.6% | Aug 6, 2018 | PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field i... |
| CVE-2018-14857 | — | — | 3.7% | Aug 6, 2018 | Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventor... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now