2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14837 | — | — | 0.7% | Aug 10, 2018 | Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. |
| CVE-2018-14503 | — | — | 0.8% | Aug 10, 2018 | Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbit... |
| CVE-2018-14028 | — | — | 17.7% | Aug 10, 2018 | In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files t... |
| CVE-2018-11492 | — | — | 11.4% | Aug 10, 2018 | ASUS HG100 devices allow denial of service via an IPv4 packet flood. |
| CVE-2018-6556 | — | — | 0.3% | Aug 10, 2018 | lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may... |
| CVE-2018-6553 | — | — | 0.4% | Aug 10, 2018 | The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possib... |
| CVE-2018-15189 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile. |
| CVE-2018-15188 | — | — | 0.9% | Aug 10, 2018 | PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure ... |
| CVE-2018-15187 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. |
| CVE-2018-15186 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. |
| CVE-2018-15185 | — | — | 0.9% | Aug 10, 2018 | PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page ... |
| CVE-2018-13390 | — | — | 0.5% | Aug 10, 2018 | Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attacke... |
| CVE-2018-10769 | — | — | 0.9% | Aug 10, 2018 | The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 t... |
| CVE-2018-7692 | — | — | 0.6% | Aug 9, 2018 | Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. |
| CVE-2018-7686 | — | — | 1.4% | Aug 9, 2018 | Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. |
| CVE-2018-10925 | HIGH | 8.1 | 2.2% | Aug 9, 2018 | It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check auth... |
| CVE-2018-14735 | — | — | 1.4% | Aug 9, 2018 | An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a ... |
| CVE-2018-10931 | CRITICAL | 9.8 | 67.9% | Aug 9, 2018 | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unaut... |
| CVE-2018-10915 | HIGH | 8.5 | 5.2% | Aug 9, 2018 | A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its inter... |
| CVE-2018-0429 | — | — | 0.5% | Aug 9, 2018 | Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows loca... |
| CVE-2018-15184 | — | — | 0.5% | Aug 9, 2018 | PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to C... |
| CVE-2018-15183 | — | — | 0.7% | Aug 9, 2018 | PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields... |
| CVE-2018-15182 | — | — | 0.5% | Aug 9, 2018 | PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields. |
| CVE-2018-15181 | — | — | 5.3% | Aug 9, 2018 | JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo... |
| CVE-2018-15133 | HIGH | 8.1 | 76.8% | Aug 9, 2018 | In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now