2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1551 | LOW | 3.1 | 1.1% | Aug 6, 2018 | IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they ... |
| CVE-2018-1528 | MEDIUM | 4.3 | 1.3% | Aug 6, 2018 | IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the... |
| CVE-2018-1422 | MEDIUM | 5.4 | 1.0% | Aug 6, 2018 | IBM Jazz Foundation products (IBM Rational DOORS Next Generation 5.0 through 5.0.2 and 6.0 through 6.0.5) are vulnerable... |
| CVE-2018-14959 | — | — | 0.5% | Aug 5, 2018 | An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI. |
| CVE-2018-14958 | — | — | 0.5% | Aug 5, 2018 | An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and descrip... |
| CVE-2018-14955 | — | — | 1.4% | Aug 5, 2018 | The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute). |
| CVE-2018-14954 | — | — | 1.6% | Aug 5, 2018 | The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute. |
| CVE-2018-14953 | — | — | 1.4% | Aug 5, 2018 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. |
| CVE-2018-14952 | — | — | 1.4% | Aug 5, 2018 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack. |
| CVE-2018-14951 | — | — | 1.4% | Aug 5, 2018 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. |
| CVE-2018-14950 | — | — | 1.4% | Aug 5, 2018 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack. |
| CVE-2018-14948 | — | — | 1.0% | Aug 5, 2018 | An issue has been found in dilawar sound through 2017-11-27. The end of openWavFile in wav-file.cc has Mismatched Memory... |
| CVE-2018-14947 | — | — | 1.6% | Aug 5, 2018 | An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines ... |
| CVE-2018-14946 | — | — | 1.6% | Aug 5, 2018 | An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routi... |
| CVE-2018-14945 | — | — | 1.1% | Aug 5, 2018 | An issue has been found in jpeg_encoder through 2015-11-27. It is a heap-based buffer overflow in the function readFromB... |
| CVE-2018-14944 | — | — | 1.0% | Aug 5, 2018 | An issue has been found in jpeg_encoder through 2015-11-27. It is a SEGV in the function readFromBMP in jpeg_encoder.cpp... |
| CVE-2018-14943 | — | — | 1.5% | Aug 5, 2018 | Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for ... |
| CVE-2018-14942 | — | — | 2.0% | Aug 5, 2018 | Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "P... |
| CVE-2018-14941 | — | — | 1.0% | Aug 5, 2018 | Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for th... |
| CVE-2018-14940 | — | — | 1.3% | Aug 5, 2018 | PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and wi... |
| CVE-2018-14939 | — | — | 2.2% | Aug 5, 2018 | The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in... |
| CVE-2018-14938 | — | — | 2.8% | Aug 5, 2018 | An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the fun... |
| CVE-2018-14937 | — | — | 0.9% | Aug 5, 2018 | The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field. |
| CVE-2018-14936 | — | — | 0.9% | Aug 5, 2018 | The Add page option in my little forum 2.4.12 allows XSS via the Title field. |
| CVE-2018-14933 | CRITICAL | 9.8 | 93.7% | Aug 4, 2018 | upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now