2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12534 | — | — | 1.5% | Jun 18, 2018 | A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress. |
| CVE-2018-12531 | — | — | 1.6% | Jun 18, 2018 | An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into con... |
| CVE-2018-12530 | — | — | 1.6% | Jun 18, 2018 | An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files vi... |
| CVE-2018-1153 | — | — | 0.5% | Jun 18, 2018 | Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests whi... |
| CVE-2018-1152 | — | — | 3.4% | Jun 18, 2018 | libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a cra... |
| CVE-2018-12533 | — | — | 21.4% | Jun 18, 2018 | JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressio... |
| CVE-2018-12532 | — | — | 7.0% | Jun 18, 2018 | JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language ... |
| CVE-2018-12525 | — | — | 7.2% | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr... |
| CVE-2018-12524 | — | — | 7.2% | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi... |
| CVE-2018-12523 | — | — | 7.2% | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi... |
| CVE-2018-12522 | — | — | 7.2% | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro... |
| CVE-2018-12104 | — | — | 1.3% | Jun 17, 2018 | Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web ... |
| CVE-2018-12073 | — | — | 0.4% | Jun 17, 2018 | An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a... |
| CVE-2018-12072 | — | — | 1.5% | Jun 17, 2018 | An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide T... |
| CVE-2018-12071 | — | — | 1.3% | Jun 17, 2018 | A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was m... |
| CVE-2018-12029 | — | — | 0.3% | Jun 17, 2018 | A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privil... |
| CVE-2018-12028 | — | — | 0.9% | Jun 17, 2018 | An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-mana... |
| CVE-2018-12027 | — | — | 1.1% | Jun 17, 2018 | An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosu... |
| CVE-2018-12026 | — | — | 1.9% | Jun 17, 2018 | During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 al... |
| CVE-2018-11219 | — | — | 7.1% | Jun 17, 2018 | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4... |
| CVE-2018-11218 | — | — | 59.4% | Jun 17, 2018 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10,... |
| CVE-2018-10997 | — | — | 1.8% | Jun 17, 2018 | Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassw... |
| CVE-2018-12338 | — | — | 1.5% | Jun 17, 2018 | Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confiden... |
| CVE-2018-12337 | — | — | 0.3% | Jun 17, 2018 | Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to par... |
| CVE-2018-12336 | — | — | 1.5% | Jun 17, 2018 | Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential inform... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now