2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11532 | — | — | 2.4% | May 29, 2018 | An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst... |
| CVE-2018-11531 | — | — | 3.0% | May 29, 2018 | Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. |
| CVE-2018-11528 | — | — | 1.6% | May 29, 2018 | WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. |
| CVE-2018-11527 | — | — | 0.6% | May 29, 2018 | An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php al... |
| CVE-2018-11523 | — | — | 9.9% | May 29, 2018 | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. |
| CVE-2018-11488 | — | — | 4.9% | May 29, 2018 | A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cau... |
| CVE-2018-10732 | — | — | 1.6% | May 28, 2018 | The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a u... |
| CVE-2018-11517 | — | — | 2.1% | May 28, 2018 | mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter valu... |
| CVE-2018-11430 | — | — | 0.6% | May 28, 2018 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t... |
| CVE-2018-11309 | — | — | 2.2% | May 28, 2018 | Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated att... |
| CVE-2018-11515 | — | — | 1.7% | May 28, 2018 | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. |
| CVE-2018-11514 | — | — | 1.1% | May 28, 2018 | PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_re... |
| CVE-2018-11512 | — | — | 2.2% | May 28, 2018 | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge... |
| CVE-2018-11508 | — | — | 1.7% | May 28, 2018 | The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv... |
| CVE-2018-11507 | — | — | 1.1% | May 28, 2018 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm ... |
| CVE-2018-6411 | — | — | 5.9% | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically ... |
| CVE-2018-6410 | — | — | 5.0% | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter. |
| CVE-2018-6409 | — | — | 14.8% | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr... |
| CVE-2018-11505 | — | — | 9.2% | May 26, 2018 | The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp... |
| CVE-2018-11504 | — | — | 1.5% | May 26, 2018 | The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of servi... |
| CVE-2018-11503 | — | — | 1.6% | May 26, 2018 | The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of s... |
| CVE-2018-11501 | — | — | 0.6% | May 26, 2018 | PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. |
| CVE-2018-11500 | — | — | 0.6% | May 26, 2018 | An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType... |
| CVE-2018-11499 | — | — | 4.0% | May 26, 2018 | A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 tha... |
| CVE-2018-11498 | — | — | 2.0% | May 26, 2018 | In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size durin... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now