2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11537 | — | — | 1.1% | Jun 19, 2018 | Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers ... |
| CVE-2018-11526 | — | — | 5.2% | Jun 19, 2018 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. |
| CVE-2018-11525 | — | — | 5.2% | Jun 19, 2018 | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. |
| CVE-2018-12583 | — | — | 0.5% | Jun 19, 2018 | An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php. |
| CVE-2018-12582 | — | — | 0.6% | Jun 19, 2018 | An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&... |
| CVE-2018-12580 | — | — | 0.6% | Jun 19, 2018 | library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 a... |
| CVE-2018-12578 | — | — | 2.1% | Jun 19, 2018 | There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of ser... |
| CVE-2018-12564 | — | — | 1.5% | Jun 19, 2018 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can f... |
| CVE-2018-12563 | — | — | 0.9% | Jun 19, 2018 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-ser... |
| CVE-2018-12562 | — | — | 1.7% | Jun 19, 2018 | An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wr... |
| CVE-2018-12561 | — | — | 1.4% | Jun 19, 2018 | An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additio... |
| CVE-2018-12560 | — | — | 1.8% | Jun 19, 2018 | An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be perform... |
| CVE-2018-12559 | — | — | 2.1% | Jun 19, 2018 | An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mo... |
| CVE-2018-12557 | — | — | 1.9% | Jun 19, 2018 | An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a ta... |
| CVE-2018-10623 | — | — | 3.6% | Jun 18, 2018 | Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buf... |
| CVE-2018-10621 | — | — | 3.6% | Jun 18, 2018 | Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer whe... |
| CVE-2018-10617 | — | — | 3.6% | Jun 18, 2018 | Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer wher... |
| CVE-2018-9029 | — | — | 1.8% | Jun 18, 2018 | An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL in... |
| CVE-2018-9028 | — | — | 0.9% | Jun 18, 2018 | Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking. |
| CVE-2018-9027 | — | — | 0.9% | Jun 18, 2018 | A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute ma... |
| CVE-2018-9026 | — | — | 1.3% | Jun 18, 2018 | A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions wit... |
| CVE-2018-9025 | — | — | 1.4% | Jun 18, 2018 | An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with s... |
| CVE-2018-9024 | — | — | 1.1% | Jun 18, 2018 | An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a... |
| CVE-2018-9023 | — | — | 1.9% | Jun 18, 2018 | An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary com... |
| CVE-2018-1333 | — | — | 17.1% | Jun 18, 2018 | By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker ex... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now