2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12919 | — | — | 0.7% | Jun 27, 2018 | In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter. |
| CVE-2018-12917 | — | — | 1.5% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c. |
| CVE-2018-12916 | — | — | 1.5% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c. |
| CVE-2018-12915 | — | — | 1.5% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a buffer over-read in calc_hash in map.c. |
| CVE-2018-12914 | — | — | 3.9% | Jun 27, 2018 | A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that conta... |
| CVE-2018-12913 | — | — | 1.5% | Jun 27, 2018 | In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to... |
| CVE-2018-12912 | — | — | 2.7% | Jun 27, 2018 | An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a... |
| CVE-2018-12909 | — | — | 18.6% | Jun 27, 2018 | Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the we... |
| CVE-2018-12908 | — | — | 10.7% | Jun 27, 2018 | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti... |
| CVE-2018-8025 | — | — | 1.8% | Jun 27, 2018 | CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP.... |
| CVE-2018-12907 | — | — | 1.3% | Jun 27, 2018 | In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to t... |
| CVE-2018-12905 | — | — | 42.2% | Jun 27, 2018 | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. |
| CVE-2018-12904 | — | — | 1.2% | Jun 27, 2018 | In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause... |
| CVE-2018-12903 | — | — | 0.6% | Jun 26, 2018 | In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on ... |
| CVE-2018-12902 | — | — | 0.7% | Jun 26, 2018 | In Easy Magazine through 2012-10-26, there is XSS in the search bar of the web site. |
| CVE-2018-12900 | — | — | 25.2% | Jun 26, 2018 | Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3... |
| CVE-2018-10594 | — | — | 69.0% | Jun 26, 2018 | Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS... |
| CVE-2018-3760 | — | — | 26.7% | Jun 26, 2018 | There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12... |
| CVE-2018-12712 | — | — | 2.3% | Jun 26, 2018 | An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, us... |
| CVE-2018-12711 | — | — | 1.4% | Jun 26, 2018 | An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, ... |
| CVE-2018-4861 | — | — | 1.9% | Jun 26, 2018 | A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the... |
| CVE-2018-4860 | — | — | 3.7% | Jun 26, 2018 | A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the... |
| CVE-2018-4859 | — | — | 3.7% | Jun 26, 2018 | A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the... |
| CVE-2018-4846 | — | — | 1.8% | Jun 26, 2018 | A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All vers... |
| CVE-2018-11449 | — | — | 0.4% | Jun 26, 2018 | A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system mi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now