2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20992 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain d... |
| CVE-2018-20990 | — | — | 1.7% | Aug 26, 2019 | An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or har... |
| CVE-2018-13367 | — | — | 0.9% | Aug 23, 2019 | An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl... |
| CVE-2018-20987 | — | — | 2.1% | Aug 22, 2019 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. |
| CVE-2018-20986 | — | — | 0.9% | Aug 22, 2019 | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho... |
| CVE-2018-20988 | — | — | 1.4% | Aug 22, 2019 | The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation. |
| CVE-2018-18573 | — | — | 2.5% | Aug 22, 2019 | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated adm... |
| CVE-2018-18572 | — | — | 2.5% | Aug 22, 2019 | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, ... |
| CVE-2018-20985 | — | — | 7.6% | Aug 22, 2019 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay... |
| CVE-2018-20984 | — | — | 2.0% | Aug 22, 2019 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. |
| CVE-2018-20983 | — | — | 0.9% | Aug 22, 2019 | The wp-retina-2x plugin before 5.2.3 for WordPress has XSS. |
| CVE-2018-20982 | — | — | 0.9% | Aug 22, 2019 | The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library a... |
| CVE-2018-20981 | — | — | 1.7% | Aug 22, 2019 | The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Expo... |
| CVE-2018-20980 | — | — | 1.4% | Aug 22, 2019 | The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. |
| CVE-2018-20979 | — | — | 2.0% | Aug 22, 2019 | The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in ... |
| CVE-2018-17791 | — | — | 1.9% | Aug 21, 2019 | Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability whe... |
| CVE-2018-20970 | — | — | 0.9% | Aug 21, 2019 | The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues. |
| CVE-2018-18056 | — | — | 0.4% | Aug 20, 2019 | An issue was discovered in the Texas Instruments (TI) TM4C, MSP432E and MSP432P microcontroller series. The eXecute-Only... |
| CVE-2018-20978 | — | — | 0.9% | Aug 20, 2019 | The wp-all-import plugin before 3.4.7 for WordPress has XSS. |
| CVE-2018-20975 | — | — | 1.2% | Aug 20, 2019 | Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb. |
| CVE-2018-20976 | — | — | 0.6% | Aug 19, 2019 | An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_f... |
| CVE-2018-20974 | — | — | 0.6% | Aug 16, 2019 | The js-jobs plugin before 1.0.7 for WordPress has CSRF. |
| CVE-2018-20973 | — | — | 2.0% | Aug 16, 2019 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. |
| CVE-2018-20972 | — | — | 0.6% | Aug 16, 2019 | The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. |
| CVE-2018-20971 | — | — | 0.6% | Aug 16, 2019 | The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now