2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8902 | — | — | 1.7% | Jun 29, 2018 | An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single sh... |
| CVE-2018-8901 | — | — | 0.7% | Jun 29, 2018 | An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access priv... |
| CVE-2018-13014 | — | — | 0.3% | Jun 29, 2018 | Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, ... |
| CVE-2018-13013 | — | — | 0.2% | Jun 29, 2018 | Improper check of unusual conditions when launching msiexec.exe in safensec.com (SysWatch service) in SAFE'N'SEC SoftCon... |
| CVE-2018-13012 | — | — | 0.5% | Jun 29, 2018 | Download of code with improper integrity check in snsupd.exe and upd.exe in SAFE'N'SEC SoftControl/SafenSoft SysWatch, S... |
| CVE-2018-13011 | — | — | 1.8% | Jun 29, 2018 | An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP... |
| CVE-2018-13010 | — | — | 0.5% | Jun 29, 2018 | WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account. |
| CVE-2018-13009 | — | — | 1.8% | Jun 29, 2018 | An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP... |
| CVE-2018-13008 | — | — | 1.8% | Jun 29, 2018 | An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP... |
| CVE-2018-13007 | — | — | 1.8% | Jun 29, 2018 | An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP... |
| CVE-2018-13006 | — | — | 2.3% | Jun 29, 2018 | An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c funct... |
| CVE-2018-13005 | — | — | 2.5% | Jun 29, 2018 | An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buff... |
| CVE-2018-13003 | — | — | 0.7% | Jun 29, 2018 | An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI. |
| CVE-2018-13002 | — | — | 0.9% | Jun 29, 2018 | An XSS issue was discovered in Inhaltsprojekte in Weblication CMS Core & Grid v12.6.24. The vulnerability is located in ... |
| CVE-2018-13001 | — | — | 0.8% | Jun 29, 2018 | An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./c... |
| CVE-2018-13000 | — | — | 0.9% | Jun 29, 2018 | An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `F... |
| CVE-2018-12999 | — | — | 8.6% | Jun 29, 2018 | Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delet... |
| CVE-2018-12996 | — | — | 3.5% | Jun 29, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) a... |
| CVE-2018-12995 | — | — | 1.2% | Jun 29, 2018 | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename ... |
| CVE-2018-12994 | — | — | 1.2% | Jun 29, 2018 | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename ... |
| CVE-2018-12993 | — | — | 1.2% | Jun 29, 2018 | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_... |
| CVE-2018-12988 | — | — | 1.6% | Jun 29, 2018 | GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI. |
| CVE-2018-12984 | — | — | 2.6% | Jun 29, 2018 | Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials. |
| CVE-2018-12983 | — | — | 1.0% | Jun 29, 2018 | A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9... |
| CVE-2018-12982 | — | — | 1.1% | Jun 29, 2018 | Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now