2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11470iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
CVE-2018-11469Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache en...
CVE-2018-11468The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of...
CVE-2018-11445A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing ...
CVE-2018-11444A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
CVE-2018-11443The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
CVE-2018-11442A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U...
CVE-2018-1137An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can als...
CVE-2018-1136An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their D...
CVE-2018-1135An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download a...
CVE-2018-1134An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download a...
CVE-2018-1133An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec...
CVE-2018-11440Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.
CVE-2018-7407An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers...
CVE-2018-7406An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers...
CVE-2018-5680This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-5679This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-5678This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-5677This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-5676This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-5675This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-5674This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ...
CVE-2018-7526In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specifi...
CVE-2018-7518In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with netwo...
CVE-2018-11419An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex fu...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now