2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16333 | — | — | 1.6% | Sep 2, 2018 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19... |
| CVE-2018-16332 | — | — | 0.6% | Sep 2, 2018 | An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability. |
| CVE-2018-16331 | — | — | 0.5% | Sep 2, 2018 | admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password. |
| CVE-2018-16330 | — | — | 0.9% | Sep 2, 2018 | Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. |
| CVE-2018-16329 | — | — | 2.3% | Sep 1, 2018 | In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/propert... |
| CVE-2018-16328 | — | — | 2.0% | Sep 1, 2018 | In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c. |
| CVE-2018-16327 | — | — | 0.6% | Sep 1, 2018 | There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration. |
| CVE-2018-16325 | — | — | 0.8% | Sep 1, 2018 | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field. |
| CVE-2018-16324 | — | — | 1.1% | Sep 1, 2018 | In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. |
| CVE-2018-16323 | MEDIUM | 6.5 | 49.3% | Sep 1, 2018 | ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha... |
| CVE-2018-16320 | — | — | 2.4% | Sep 1, 2018 | idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code f... |
| CVE-2018-16316 | — | — | 0.8% | Sep 1, 2018 | A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to injec... |
| CVE-2018-16315 | — | — | 0.4% | Sep 1, 2018 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=a... |
| CVE-2018-16314 | — | — | 0.7% | Sep 1, 2018 | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exis... |
| CVE-2018-16313 | — | — | 0.7% | Sep 1, 2018 | Bludit 2.3.4 allows XSS via a user name. |
| CVE-2018-16308 | — | — | 1.8% | Sep 1, 2018 | The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. |
| CVE-2018-16303 | — | — | 1.6% | Sep 1, 2018 | PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a c... |
| CVE-2018-16302 | — | — | 4.3% | Sep 1, 2018 | MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file. |
| CVE-2018-15161 | — | — | 1.5% | Sep 1, 2018 | The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause ... |
| CVE-2018-15160 | — | — | 1.5% | Sep 1, 2018 | The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows rem... |
| CVE-2018-15159 | — | — | 1.5% | Sep 1, 2018 | The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause ... |
| CVE-2018-15158 | — | — | 1.5% | Sep 1, 2018 | The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to caus... |
| CVE-2018-15157 | — | — | 1.5% | Sep 1, 2018 | The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a... |
| CVE-2018-15514 | — | — | 2.5% | Sep 1, 2018 | HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deseria... |
| CVE-2018-16298 | — | — | 0.9% | Aug 31, 2018 | An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now