2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11376 | — | — | 1.1% | May 22, 2018 | The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-boun... |
| CVE-2018-11375 | — | — | 1.1% | May 22, 2018 | The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bound... |
| CVE-2018-11373 | — | — | 1.2% | May 22, 2018 | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. |
| CVE-2018-11372 | — | — | 1.2% | May 22, 2018 | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. |
| CVE-2018-11371 | — | — | 0.7% | May 22, 2018 | SkyCaiji 1.2 allows CSRF to add an Administrator user. |
| CVE-2018-6378 | — | — | 1.4% | May 22, 2018 | In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the m... |
| CVE-2018-11369 | — | — | 1.1% | May 22, 2018 | An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the databas... |
| CVE-2018-11328 | — | — | 1.4% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI contain... |
| CVE-2018-11327 | — | — | 1.4% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were... |
| CVE-2018-11326 | — | — | 1.1% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities... |
| CVE-2018-11325 | — | — | 3.8% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after e... |
| CVE-2018-11324 | — | — | 1.3% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core ... |
| CVE-2018-11323 | — | — | 3.2% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of use... |
| CVE-2018-11322 | — | — | 2.1% | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled... |
| CVE-2018-11321 | — | — | 2.0% | May 22, 2018 | An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to crea... |
| CVE-2018-6963 | — | — | 0.4% | May 22, 2018 | VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabiliti... |
| CVE-2018-6962 | — | — | 0.4% | May 22, 2018 | VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalat... |
| CVE-2018-1583 | — | — | 0.8% | May 22, 2018 | IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-c... |
| CVE-2018-11367 | — | — | 1.1% | May 22, 2018 | An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module. |
| CVE-2018-11366 | — | — | 2.2% | May 22, 2018 | init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS)... |
| CVE-2018-3640 | — | — | 7.6% | May 22, 2018 | Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may ... |
| CVE-2018-11365 | — | — | 1.2% | May 22, 2018 | sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop. |
| CVE-2018-11364 | — | — | 1.2% | May 22, 2018 | sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak r... |
| CVE-2018-11363 | — | — | 1.9% | May 22, 2018 | jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read. |
| CVE-2018-11346 | — | — | 1.3% | May 22, 2018 | An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability t... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now