2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11781 | — | — | 1.0% | Sep 17, 2018 | Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. |
| CVE-2018-11780 | — | — | 10.8% | Sep 17, 2018 | A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. |
| CVE-2018-17140 | — | — | 0.7% | Sep 17, 2018 | The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp... |
| CVE-2018-17139 | — | — | 3.1% | Sep 17, 2018 | UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /product... |
| CVE-2018-17138 | — | — | 0.7% | Sep 17, 2018 | The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php... |
| CVE-2018-17137 | — | — | 1.4% | Sep 17, 2018 | Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, wh... |
| CVE-2018-17136 | — | — | 1.2% | Sep 17, 2018 | zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. |
| CVE-2018-17134 | — | — | 1.8% | Sep 17, 2018 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjuncti... |
| CVE-2018-17133 | — | — | 1.8% | Sep 17, 2018 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. |
| CVE-2018-17132 | — | — | 1.8% | Sep 17, 2018 | admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter... |
| CVE-2018-17131 | — | — | 1.8% | Sep 17, 2018 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. |
| CVE-2018-17130 | — | — | 0.5% | Sep 17, 2018 | PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, |
| CVE-2018-17129 | — | — | 0.9% | Sep 17, 2018 | MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field... |
| CVE-2018-17128 | — | — | 74.8% | Sep 17, 2018 | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. |
| CVE-2018-17127 | — | — | 1.5% | Sep 17, 2018 | blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of se... |
| CVE-2018-17126 | — | — | 3.2% | Sep 17, 2018 | CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Ins... |
| CVE-2018-17125 | — | — | 1.4% | Sep 17, 2018 | CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php. |
| CVE-2018-17113 | — | — | 0.6% | Sep 17, 2018 | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or m... |
| CVE-2018-17110 | — | — | 1.6% | Sep 17, 2018 | Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the managemen... |
| CVE-2018-16309 | — | — | — | Sep 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-17108 | — | — | 1.1% | Sep 16, 2018 | The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeove... |
| CVE-2018-17106 | — | — | 0.9% | Sep 16, 2018 | In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An... |
| CVE-2018-17104 | — | — | 0.8% | Sep 16, 2018 | An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrat... |
| CVE-2018-17103 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's pass... |
| CVE-2018-17102 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrat... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now