2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12810Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Succes...
CVE-2018-12808Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier...
CVE-2018-12807Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful ...
CVE-2018-12806Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Succe...
CVE-2018-12799Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier...
CVE-2018-16062MEDIUM5.5dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial ...
CVE-2018-15882An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically pr...
CVE-2018-15881An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violati...
CVE-2018-15880An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a s...
CVE-2018-15121An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state ...
CVE-2018-15897PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript...
CVE-2018-15896PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
CVE-2018-3916HIGH7.8An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-6643Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.
CVE-2018-3908HIGH7.5An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET...
CVE-2018-3895HIGH8.8An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa...
CVE-2018-15901e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including admini...
CVE-2018-15884RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
CVE-2018-15873CRITICAL9.8A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
CVE-2018-15740MEDIUM6.1Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
CVE-2018-15608Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
CVE-2018-15596An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can gener...
CVE-2018-14572In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a...
CVE-2018-14400Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-3926MEDIUM5.5An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now