2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17046 | — | — | 0.7% | Sep 14, 2018 | translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js. |
| CVE-2018-17045 | — | — | 0.5% | Sep 14, 2018 | An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator passw... |
| CVE-2018-17044 | — | — | 0.5% | Sep 14, 2018 | In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter. |
| CVE-2018-17043 | — | — | 1.1% | Sep 14, 2018 | An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init ... |
| CVE-2018-17042 | — | — | 0.8% | Sep 14, 2018 | An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop. |
| CVE-2018-17039 | — | — | 0.9% | Sep 14, 2018 | MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled... |
| CVE-2018-17037 | — | — | 1.0% | Sep 14, 2018 | user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superu... |
| CVE-2018-17036 | CRITICAL | 9.8 | 1.7% | Sep 14, 2018 | An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain par... |
| CVE-2018-17035 | — | — | 1.1% | Sep 14, 2018 | UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. |
| CVE-2018-17034 | — | — | 0.7% | Sep 14, 2018 | UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter. |
| CVE-2018-17031 | — | — | 0.9% | Sep 14, 2018 | In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstra... |
| CVE-2018-17030 | — | — | 2.3% | Sep 14, 2018 | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code v... |
| CVE-2018-17026 | — | — | 0.7% | Sep 13, 2018 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, ... |
| CVE-2018-17025 | — | — | 0.9% | Sep 13, 2018 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with... |
| CVE-2018-17024 | — | — | 0.7% | Sep 13, 2018 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action. |
| CVE-2018-17023 | — | — | 0.6% | Sep 13, 2018 | Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows... |
| CVE-2018-17022 | — | — | 2.2% | Sep 13, 2018 | Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a de... |
| CVE-2018-17021 | — | — | 1.1% | Sep 13, 2018 | Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote... |
| CVE-2018-17020 | — | — | 2.1% | Sep 13, 2018 | ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a... |
| CVE-2018-17019 | — | — | 1.4% | Sep 13, 2018 | In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc. |
| CVE-2018-1330 | — | — | 3.6% | Sep 13, 2018 | When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught... |
| CVE-2018-10637 | — | — | 1.8% | Sep 13, 2018 | A maliciously crafted project file may cause a buffer overflow, which may allow the attacker to execute arbitrary code t... |
| CVE-2018-17018 | — | — | 1.0% | Sep 13, 2018 | An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras... |
| CVE-2018-17017 | — | — | 1.0% | Sep 13, 2018 | An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras... |
| CVE-2018-17016 | — | — | 1.0% | Sep 13, 2018 | An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can cras... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now