2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11097An issue was discovered in cloudwu/cstring through 2016-11-09. There is a memory leak vulnerability that could lead to a...
CVE-2018-11095The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file si...
CVE-2018-11090An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker t...
CVE-2018-10994js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
CVE-2018-8843Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing speci...
CVE-2018-10991Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10990. Reason: This candidate is a reservation...
CVE-2018-10252An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely ge...
CVE-2018-5230The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 ...
CVE-2018-0591The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates f...
CVE-2018-0590Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr...
CVE-2018-0589Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr...
CVE-2018-0588Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress al...
CVE-2018-0587Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote auth...
CVE-2018-0586Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr...
CVE-2018-0585Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attacker...
CVE-2018-0583Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attacker...
CVE-2018-0582Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers t...
CVE-2018-0581Cross-site scripting vulnerability in ASUS RT-AC87U Firmware version prior to 3.0.0.4.378.9383 allows remote attackers t...
CVE-2018-0580Untrusted search path vulnerability in CELSYS, Inc CLIP STUDIO series (CLIP STUDIO PAINT (for Windows) EX/PRO/DEBUT Ver....
CVE-2018-0579Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2...
CVE-2018-0578Cross-site scripting vulnerability in PixelYourSite plugin prior to version 5.3.0 for WordPress allows remote attackers ...
CVE-2018-0576Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers t...
CVE-2018-0568Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated us...
CVE-2018-11037In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an informat...
CVE-2018-11035In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now