2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0653 | — | — | 0.9% | Sep 7, 2018 | Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script ... |
| CVE-2018-0652 | — | — | 0.7% | Sep 7, 2018 | Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra... |
| CVE-2018-0650 | — | — | 0.6% | Sep 7, 2018 | The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers,... |
| CVE-2018-0649 | — | — | 1.1% | Sep 7, 2018 | Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart ... |
| CVE-2018-0648 | — | — | 0.8% | Sep 7, 2018 | Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacke... |
| CVE-2018-0647 | — | — | 0.6% | Sep 7, 2018 | Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers ... |
| CVE-2018-0645 | — | — | 2.4% | Sep 7, 2018 | MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors. |
| CVE-2018-0644 | — | — | 1.0% | Sep 7, 2018 | Buffer overflow in Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-client2) 1:1.4.9+p41-u4jma1 and ear... |
| CVE-2018-0643 | — | — | 0.5% | Sep 7, 2018 | Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker... |
| CVE-2018-0642 | — | — | 1.0% | Sep 7, 2018 | Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitr... |
| CVE-2018-0624 | — | — | 1.2% | Sep 7, 2018 | Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier,... |
| CVE-2018-0623 | — | — | 1.0% | Sep 7, 2018 | Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier,... |
| CVE-2018-16655 | — | — | 0.7% | Sep 7, 2018 | Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. |
| CVE-2018-16654 | — | — | 0.8% | Sep 7, 2018 | Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. |
| CVE-2018-16653 | — | — | 0.7% | Sep 7, 2018 | rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter. |
| CVE-2018-16651 | — | — | 1.4% | Sep 7, 2018 | The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports. |
| CVE-2018-16650 | — | — | 0.5% | Sep 7, 2018 | phpMyFAQ before 2.9.11 allows CSRF. |
| CVE-2018-6320 | — | — | 4.1% | Sep 6, 2018 | A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3R... |
| CVE-2018-16648 | — | — | 1.5% | Sep 6, 2018 | In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of servi... |
| CVE-2018-16647 | — | — | 1.5% | Sep 6, 2018 | In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of ... |
| CVE-2018-16646 | — | — | 2.9% | Sep 6, 2018 | In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote ... |
| CVE-2018-16590 | — | — | 2.4% | Sep 6, 2018 | FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication. |
| CVE-2018-16517 | MEDIUM | 5.5 | 5.2% | Sep 6, 2018 | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni... |
| CVE-2018-16310 | — | — | 1.2% | Sep 6, 2018 | Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of ran... |
| CVE-2018-16285 | — | — | 1.3% | Sep 6, 2018 | The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now