2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11034 | — | — | 1.0% | May 14, 2018 | In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser... |
| CVE-2018-10944 | — | — | 1.0% | May 14, 2018 | The request_dividend function of a smart contract implementation for ROC (aka Rasputin Online Coin), an Ethereum ERC20 t... |
| CVE-2018-11033 | — | — | 1.3% | May 14, 2018 | The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause... |
| CVE-2018-11032 | — | — | 1.5% | May 14, 2018 | PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function. |
| CVE-2018-11031 | — | — | 2.0% | May 14, 2018 | application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an a... |
| CVE-2018-11018 | — | — | 0.6% | May 13, 2018 | An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/sys... |
| CVE-2018-11017 | — | — | 1.4% | May 13, 2018 | The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size gr... |
| CVE-2018-10678 | — | — | 1.0% | May 13, 2018 | MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes i... |
| CVE-2018-11013 | — | — | 6.5% | May 13, 2018 | Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware vers... |
| CVE-2018-11012 | — | — | 0.6% | May 12, 2018 | ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController... |
| CVE-2018-11011 | — | — | 0.6% | May 12, 2018 | ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java. |
| CVE-2018-11004 | — | — | 0.6% | May 12, 2018 | An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/adm... |
| CVE-2018-11003 | — | — | 0.7% | May 12, 2018 | An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controll... |
| CVE-2018-10999 | — | — | 2.4% | May 12, 2018 | An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer ove... |
| CVE-2018-10996 | — | — | 5.4% | May 12, 2018 | The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or c... |
| CVE-2018-10992 | — | — | 1.5% | May 11, 2018 | lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWS... |
| CVE-2018-6619 | — | — | 0.4% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use... |
| CVE-2018-6618 | — | — | 0.5% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext pa... |
| CVE-2018-6617 | — | — | 0.4% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of a... |
| CVE-2018-6458 | — | — | 10.5% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attack... |
| CVE-2018-6362 | — | — | 1.1% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the P... |
| CVE-2018-6361 | — | — | 39.6% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP acco... |
| CVE-2018-6023 | — | — | 2.4% | May 11, 2018 | Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act... |
| CVE-2018-5304 | — | — | 0.8% | May 11, 2018 | An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vuln... |
| CVE-2018-5303 | — | — | 0.5% | May 11, 2018 | An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the w... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now