2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000664 | — | — | 0.5% | Sep 6, 2018 | daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnera... |
| CVE-2018-1000663 | — | — | 0.9% | Sep 6, 2018 | jsish version 2.4.70 2.047 contains a Buffer Overflow vulnerability in function _jsi_evalcode from jsiEval.c that can re... |
| CVE-2018-1000661 | — | — | 0.9% | Sep 6, 2018 | jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can ... |
| CVE-2018-1000660 | — | — | 1.3% | Sep 6, 2018 | TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b... |
| CVE-2018-1000659 | — | — | 3.6% | Sep 6, 2018 | LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulne... |
| CVE-2018-1000658 | — | — | 2.1% | Sep 6, 2018 | LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an at... |
| CVE-2018-16606 | — | — | 5.9% | Sep 6, 2018 | In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted paper... |
| CVE-2018-16604 | — | — | 1.5% | Sep 6, 2018 | An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary P... |
| CVE-2018-1000773 | — | — | 7.3% | Sep 6, 2018 | WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can re... |
| CVE-2018-1695 | HIGH | 7.3 | 2.2% | Sep 6, 2018 | IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to con... |
| CVE-2018-16585 | — | — | 1.7% | Sep 6, 2018 | An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even th... |
| CVE-2018-14632 | HIGH | 7.7 | 1.9% | Sep 6, 2018 | An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Contai... |
| CVE-2018-14624 | HIGH | 7.5 | 2.5% | Sep 6, 2018 | A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the ... |
| CVE-2018-11263 | — | — | 0.5% | Sep 6, 2018 | In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is ... |
| CVE-2018-16459 | — | — | 0.8% | Sep 6, 2018 | An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser. |
| CVE-2018-1000673 | — | — | — | Sep 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000773. Reason: This candidate is a reservati... |
| CVE-2018-16552 | HIGH | 8.8 | 0.6% | Sep 5, 2018 | MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs. |
| CVE-2018-16551 | — | — | 0.7% | Sep 5, 2018 | LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit. |
| CVE-2018-16550 | — | — | 3.6% | Sep 5, 2018 | TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by sk... |
| CVE-2018-16549 | — | — | 2.5% | Sep 5, 2018 | HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter. |
| CVE-2018-16548 | — | — | 2.0% | Sep 5, 2018 | An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_d... |
| CVE-2018-16381 | — | — | 0.7% | Sep 5, 2018 | e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter. |
| CVE-2018-16361 | — | — | 0.9% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter. |
| CVE-2018-16307 | — | — | 2.0% | Sep 5, 2018 | An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible ... |
| CVE-2018-16252 | — | — | 2.5% | Sep 5, 2018 | FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now