2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11097 | — | — | 1.1% | May 15, 2018 | An issue was discovered in cloudwu/cstring through 2016-11-09. There is a memory leak vulnerability that could lead to a... |
| CVE-2018-11095 | — | — | 1.8% | May 15, 2018 | The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file si... |
| CVE-2018-11090 | — | — | 0.7% | May 14, 2018 | An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker t... |
| CVE-2018-10994 | — | — | 1.4% | May 14, 2018 | js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL. |
| CVE-2018-8843 | — | — | 2.0% | May 14, 2018 | Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing speci... |
| CVE-2018-10991 | — | — | — | May 14, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10990. Reason: This candidate is a reservation... |
| CVE-2018-10252 | — | — | 0.9% | May 14, 2018 | An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely ge... |
| CVE-2018-5230 | — | — | 37.6% | May 14, 2018 | The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 ... |
| CVE-2018-0591 | — | — | 0.9% | May 14, 2018 | The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates f... |
| CVE-2018-0590 | — | — | 1.1% | May 14, 2018 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr... |
| CVE-2018-0589 | — | — | 1.1% | May 14, 2018 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr... |
| CVE-2018-0588 | — | — | 2.6% | May 14, 2018 | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress al... |
| CVE-2018-0587 | — | — | 1.1% | May 14, 2018 | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote auth... |
| CVE-2018-0586 | — | — | 1.6% | May 14, 2018 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr... |
| CVE-2018-0585 | — | — | 1.0% | May 14, 2018 | Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attacker... |
| CVE-2018-0583 | — | — | 0.9% | May 14, 2018 | Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attacker... |
| CVE-2018-0582 | — | — | 0.9% | May 14, 2018 | Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers t... |
| CVE-2018-0581 | — | — | 0.9% | May 14, 2018 | Cross-site scripting vulnerability in ASUS RT-AC87U Firmware version prior to 3.0.0.4.378.9383 allows remote attackers t... |
| CVE-2018-0580 | — | — | 2.1% | May 14, 2018 | Untrusted search path vulnerability in CELSYS, Inc CLIP STUDIO series (CLIP STUDIO PAINT (for Windows) EX/PRO/DEBUT Ver.... |
| CVE-2018-0579 | — | — | 1.1% | May 14, 2018 | Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2... |
| CVE-2018-0578 | — | — | 0.8% | May 14, 2018 | Cross-site scripting vulnerability in PixelYourSite plugin prior to version 5.3.0 for WordPress allows remote attackers ... |
| CVE-2018-0576 | — | — | 1.5% | May 14, 2018 | Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers t... |
| CVE-2018-0568 | — | — | 1.7% | May 14, 2018 | Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated us... |
| CVE-2018-11037 | — | — | 2.4% | May 14, 2018 | In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an informat... |
| CVE-2018-11035 | — | — | 0.4% | May 14, 2018 | In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now