2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11559 | — | — | 0.7% | May 30, 2018 | DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter. |
| CVE-2018-11558 | — | — | 0.7% | May 30, 2018 | DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter. |
| CVE-2018-11557 | — | — | 0.6% | May 30, 2018 | YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter. |
| CVE-2018-11556 | — | — | 1.1% | May 30, 2018 | tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in lib... |
| CVE-2018-11555 | — | — | 1.1% | May 30, 2018 | tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a... |
| CVE-2018-11550 | — | — | — | May 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9850. Reason: This candidate is a reservation ... |
| CVE-2018-11235 | — | — | 49.2% | May 30, 2018 | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote... |
| CVE-2018-11233 | — | — | 4.3% | May 30, 2018 | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code t... |
| CVE-2018-11549 | — | — | 0.7% | May 29, 2018 | An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> ... |
| CVE-2018-11548 | — | — | 1.3% | May 29, 2018 | An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connectio... |
| CVE-2018-11547 | — | — | 1.6% | May 29, 2018 | md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandl... |
| CVE-2018-11546 | — | — | 1.6% | May 29, 2018 | md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error. |
| CVE-2018-11545 | — | — | 1.6% | May 29, 2018 | md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link lab... |
| CVE-2018-10755 | — | — | — | May 29, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific pr... |
| CVE-2018-6964 | — | — | 0.4% | May 29, 2018 | VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to ... |
| CVE-2018-11392 | — | — | 4.6% | May 29, 2018 | An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.... |
| CVE-2018-11027 | — | — | 0.8% | May 29, 2018 | A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2018-10751 | — | — | 8.7% | May 29, 2018 | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex... |
| CVE-2018-10466 | — | — | 8.3% | May 29, 2018 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. |
| CVE-2018-1242 | — | — | 2.8% | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command inj... |
| CVE-2018-1241 | — | — | 1.6% | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditio... |
| CVE-2018-1235 | — | — | 43.3% | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje... |
| CVE-2018-5241 | — | — | 4.8% | May 29, 2018 | Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authenticati... |
| CVE-2018-11536 | — | — | 1.7% | May 29, 2018 | md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits. |
| CVE-2018-11535 | — | — | 3.3% | May 29, 2018 | An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now