2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10536 | — | — | 2.0% | Apr 29, 2018 | An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writ... |
| CVE-2018-10535 | — | — | 2.3% | Apr 29, 2018 | The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU... |
| CVE-2018-10534 | — | — | 1.9% | Apr 29, 2018 | The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka lib... |
| CVE-2018-10529 | — | — | 1.9% | Apr 29, 2018 | An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implement... |
| CVE-2018-10527 | — | — | 0.5% | Apr 28, 2018 | EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and cont... |
| CVE-2018-10468 | — | — | 1.6% | Apr 28, 2018 | The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, ... |
| CVE-2018-10523 | — | — | 1.2% | Apr 27, 2018 | CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.a... |
| CVE-2018-10522 | — | — | 1.0% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive informat... |
| CVE-2018-10521 | — | — | 0.9% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file mo... |
| CVE-2018-10520 | — | — | 1.0% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary fil... |
| CVE-2018-10519 | — | — | 1.0% | Apr 27, 2018 | CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arrangin... |
| CVE-2018-10518 | — | — | 1.0% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file ... |
| CVE-2018-10517 | — | — | 15.5% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex... |
| CVE-2018-10516 | — | — | 1.2% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive inform... |
| CVE-2018-10515 | — | — | 2.4% | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code exec... |
| CVE-2018-7669 | — | — | 17.5% | Apr 27, 2018 | An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application... |
| CVE-2018-10504 | — | — | 4.7% | Apr 27, 2018 | The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. |
| CVE-2018-1479 | — | — | 0.7% | Apr 27, 2018 | IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute mal... |
| CVE-2018-1475 | — | — | 2.2% | Apr 27, 2018 | IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute f... |
| CVE-2018-1473 | — | — | 0.9% | Apr 27, 2018 | IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-1471 | — | — | — | Apr 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-10472 | — | — | 0.4% | Apr 27, 2018 | An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitr... |
| CVE-2018-10471 | — | — | 0.4% | Apr 27, 2018 | An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds... |
| CVE-2018-10469 | — | — | 2.2% | Apr 27, 2018 | b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] paramete... |
| CVE-2018-7527 | — | — | 0.7% | Apr 26, 2018 | A buffer overflow can be triggered in LeviStudio HMI Editor, Version 1.10 part of Wecon LeviStudioU 1.8.29, and PI Studi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now