2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16408 | — | — | 4.7% | Sep 3, 2018 | D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTom... |
| CVE-2018-16407 | — | — | 1.2% | Sep 3, 2018 | An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. |
| CVE-2018-16406 | — | — | 1.3% | Sep 3, 2018 | An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. |
| CVE-2018-16405 | — | — | 1.3% | Sep 3, 2018 | An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. |
| CVE-2018-16403 | — | — | 1.2% | Sep 3, 2018 | libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dw... |
| CVE-2018-16402 | CRITICAL | 9.8 | 3.7% | Sep 3, 2018 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application cra... |
| CVE-2018-16398 | — | — | 1.4% | Sep 3, 2018 | In Twistlock AuthZ Broker 0.1, regular expressions are mishandled, as demonstrated by containers/aa/pause?aaa=\/start to... |
| CVE-2018-16397 | — | — | 1.0% | Sep 3, 2018 | In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file, |
| CVE-2018-16393 | — | — | 0.6% | Sep 3, 2018 | Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15... |
| CVE-2018-16392 | — | — | 0.6% | Sep 3, 2018 | Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC... |
| CVE-2018-16391 | — | — | 0.7% | Sep 3, 2018 | Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in O... |
| CVE-2018-16387 | — | — | 0.7% | Sep 3, 2018 | An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add. |
| CVE-2018-16385 | — | — | 2.1% | Sep 3, 2018 | ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string. |
| CVE-2018-16384 | HIGH | 7.5 | 1.7% | Sep 3, 2018 | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0... |
| CVE-2018-16382 | — | — | 1.0% | Sep 3, 2018 | Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c. |
| CVE-2018-16380 | — | — | 0.6% | Sep 3, 2018 | An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add a... |
| CVE-2018-16379 | — | — | 0.6% | Sep 3, 2018 | Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen. |
| CVE-2018-16376 | — | — | 2.6% | Sep 3, 2018 | An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet ... |
| CVE-2018-16375 | — | — | 2.4% | Sep 3, 2018 | An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function p... |
| CVE-2018-16374 | — | — | 0.6% | Sep 3, 2018 | Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings. |
| CVE-2018-16373 | — | — | 1.1% | Sep 3, 2018 | Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save. |
| CVE-2018-16372 | — | — | 0.7% | Sep 3, 2018 | The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw p... |
| CVE-2018-16371 | — | — | 0.7% | Sep 3, 2018 | PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_gr... |
| CVE-2018-16370 | — | — | 1.8% | Sep 3, 2018 | In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by... |
| CVE-2018-16369 | — | — | 1.6% | Sep 3, 2018 | XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a craft... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now