2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10933 | CRITICAL | 9.1 | 91.8% | Oct 17, 2018 | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul... |
| CVE-2018-18436 | HIGH | 8.8 | 0.5% | Oct 17, 2018 | JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. |
| CVE-2018-18434 | — | — | 2.4% | Oct 17, 2018 | An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava... |
| CVE-2018-18433 | — | — | 0.6% | Oct 17, 2018 | An issue was discovered in DESTOON B2B 7.0. admin/category.inc.php has XSS via the category[catname] parameter to the ad... |
| CVE-2018-18432 | — | — | 0.5% | Oct 17, 2018 | An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request. |
| CVE-2018-18431 | — | — | 0.6% | Oct 17, 2018 | An issue was discovered in DESTOON B2B 7.0. XSS exists via certain text boxes to the admin.php?moduleid=2&action=add URI... |
| CVE-2018-18430 | — | — | 0.6% | Oct 17, 2018 | An issue was discovered in DESTOON B2B 7.0. admin\setting.inc.php has XSS via the first text box to the admin.php URI. |
| CVE-2018-18427 | — | — | 1.2% | Oct 17, 2018 | s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php. |
| CVE-2018-18426 | — | — | 2.4% | Oct 17, 2018 | s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow va... |
| CVE-2018-18422 | — | — | 0.5% | Oct 17, 2018 | UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI. |
| CVE-2018-18409 | — | — | 1.3% | Oct 17, 2018 | A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing... |
| CVE-2018-18408 | — | — | 2.3% | Oct 17, 2018 | A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the functi... |
| CVE-2018-18407 | — | — | 1.2% | Oct 17, 2018 | A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the increment... |
| CVE-2018-3955 | HIGH | 7.2 | 4.8% | Oct 17, 2018 | An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware ... |
| CVE-2018-3954 | HIGH | 7.2 | 3.4% | Oct 17, 2018 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version... |
| CVE-2018-3953 | HIGH | 7.2 | 13.3% | Oct 17, 2018 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version... |
| CVE-2018-17911 | HIGH | 7.8 | 3.2% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remo... |
| CVE-2018-17901 | — | — | 1.6% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input p... |
| CVE-2018-17899 | — | — | 8.1% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution. |
| CVE-2018-17897 | — | — | 6.0% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may al... |
| CVE-2018-17895 | — | — | 4.8% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code e... |
| CVE-2018-17893 | — | — | 6.4% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote co... |
| CVE-2018-3302 | — | — | 1.5% | Oct 17, 2018 | Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter... |
| CVE-2018-3301 | — | — | 1.5% | Oct 17, 2018 | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core T... |
| CVE-2018-3299 | — | — | 1.8% | Oct 17, 2018 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4,... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now