2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11470 | — | — | 1.1% | May 25, 2018 | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. |
| CVE-2018-11469 | — | — | 3.1% | May 25, 2018 | Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache en... |
| CVE-2018-11468 | — | — | 1.5% | May 25, 2018 | The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of... |
| CVE-2018-11445 | — | — | 2.4% | May 25, 2018 | A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing ... |
| CVE-2018-11444 | — | — | 3.3% | May 25, 2018 | A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. |
| CVE-2018-11443 | — | — | 2.7% | May 25, 2018 | The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. |
| CVE-2018-11442 | — | — | 2.4% | May 25, 2018 | A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U... |
| CVE-2018-1137 | — | — | 1.7% | May 25, 2018 | An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can als... |
| CVE-2018-1136 | — | — | 1.1% | May 25, 2018 | An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their D... |
| CVE-2018-1135 | — | — | 1.2% | May 25, 2018 | An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download a... |
| CVE-2018-1134 | — | — | 1.0% | May 25, 2018 | An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download a... |
| CVE-2018-1133 | — | — | 32.2% | May 25, 2018 | An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec... |
| CVE-2018-11440 | — | — | 3.2% | May 25, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c. |
| CVE-2018-7407 | — | — | 4.0% | May 24, 2018 | An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers... |
| CVE-2018-7406 | — | — | 4.0% | May 24, 2018 | An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers... |
| CVE-2018-5680 | — | — | 3.4% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-5679 | — | — | 4.1% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-5678 | — | — | 4.1% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-5677 | — | — | 4.1% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-5676 | — | — | 3.4% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-5675 | — | — | 4.0% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-5674 | — | — | 4.1% | May 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before ... |
| CVE-2018-7526 | — | — | 1.3% | May 24, 2018 | In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specifi... |
| CVE-2018-7518 | — | — | 1.3% | May 24, 2018 | In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with netwo... |
| CVE-2018-11419 | — | — | 1.6% | May 24, 2018 | An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex fu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now