2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16368 | — | — | 1.1% | Sep 3, 2018 | SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (he... |
| CVE-2018-16367 | — | — | 2.2% | Sep 2, 2018 | In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can... |
| CVE-2018-16366 | — | — | 0.6% | Sep 2, 2018 | An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF. |
| CVE-2018-16365 | — | — | 0.6% | Sep 2, 2018 | An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF. |
| CVE-2018-16362 | MEDIUM | 6.1 | 1.6% | Sep 2, 2018 | An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site sc... |
| CVE-2018-16359 | — | — | 0.5% | Sep 2, 2018 | Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows at... |
| CVE-2018-16358 | — | — | 0.7% | Sep 2, 2018 | A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1... |
| CVE-2018-16354 | — | — | 1.1% | Sep 2, 2018 | An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit paramete... |
| CVE-2018-16353 | — | — | 1.1% | Sep 2, 2018 | An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit par... |
| CVE-2018-16352 | — | — | 1.4% | Sep 2, 2018 | There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .... |
| CVE-2018-16350 | — | — | 0.9% | Sep 2, 2018 | WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter. |
| CVE-2018-16349 | — | — | 0.9% | Sep 2, 2018 | WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter. |
| CVE-2018-16348 | — | — | 0.6% | Sep 2, 2018 | SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name. |
| CVE-2018-16347 | — | — | 0.8% | Sep 2, 2018 | An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize. |
| CVE-2018-16346 | — | — | 0.6% | Sep 2, 2018 | ChemCMS 1.0.6 has XSS via the "setting -> website information" field. |
| CVE-2018-16345 | — | — | 0.5% | Sep 2, 2018 | An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s... |
| CVE-2018-16344 | — | — | 1.9% | Sep 2, 2018 | An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal seque... |
| CVE-2018-16343 | — | — | 2.7% | Sep 2, 2018 | SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block... |
| CVE-2018-16342 | — | — | 0.6% | Sep 2, 2018 | ShowDoc v1.8.0 has XSS via a new page. |
| CVE-2018-16339 | — | — | 0.5% | Sep 2, 2018 | An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/u... |
| CVE-2018-16338 | — | — | 0.5% | Sep 2, 2018 | An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via a... |
| CVE-2018-16337 | — | — | 0.4% | Sep 2, 2018 | An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration v... |
| CVE-2018-16336 | — | — | 2.7% | Sep 2, 2018 | Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based... |
| CVE-2018-16335 | — | — | 2.6% | Sep 2, 2018 | newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause ... |
| CVE-2018-16334 | — | — | 3.6% | Sep 2, 2018 | An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now