2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12810 | — | — | 6.5% | Aug 29, 2018 | Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Succes... |
| CVE-2018-12808 | — | — | 7.5% | Aug 29, 2018 | Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier... |
| CVE-2018-12807 | — | — | 4.9% | Aug 29, 2018 | Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful ... |
| CVE-2018-12806 | — | — | 3.9% | Aug 29, 2018 | Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Succe... |
| CVE-2018-12799 | — | — | 6.7% | Aug 29, 2018 | Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier... |
| CVE-2018-16062 | MEDIUM | 5.5 | 1.7% | Aug 29, 2018 | dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial ... |
| CVE-2018-15882 | — | — | 2.9% | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically pr... |
| CVE-2018-15881 | — | — | 2.2% | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate checks regarding disabled fields can lead to an ACL violati... |
| CVE-2018-15880 | — | — | 1.0% | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a s... |
| CVE-2018-15121 | — | — | 0.5% | Aug 29, 2018 | An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state ... |
| CVE-2018-15897 | — | — | 1.1% | Aug 28, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript... |
| CVE-2018-15896 | — | — | 0.5% | Aug 28, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name. |
| CVE-2018-3916 | HIGH | 7.8 | 0.4% | Aug 28, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-6643 | — | — | 0.8% | Aug 28, 2018 | Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter. |
| CVE-2018-3908 | HIGH | 7.5 | 1.3% | Aug 28, 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET... |
| CVE-2018-3895 | HIGH | 8.8 | 1.8% | Aug 28, 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa... |
| CVE-2018-15901 | — | — | 0.6% | Aug 28, 2018 | e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including admini... |
| CVE-2018-15884 | — | — | 2.5% | Aug 28, 2018 | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. |
| CVE-2018-15873 | CRITICAL | 9.8 | 1.1% | Aug 28, 2018 | A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter. |
| CVE-2018-15740 | MEDIUM | 6.1 | 6.1% | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. |
| CVE-2018-15608 | — | — | 2.5% | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. |
| CVE-2018-15596 | — | — | 2.3% | Aug 28, 2018 | An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can gener... |
| CVE-2018-14572 | — | — | 2.4% | Aug 28, 2018 | In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a... |
| CVE-2018-14400 | — | — | — | Aug 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-3926 | MEDIUM | 5.5 | 0.4% | Aug 28, 2018 | An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now