2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9060 | — | — | — | Apr 24, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-7932 | — | — | 0.4% | Apr 24, 2018 | Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a ... |
| CVE-2018-7931 | — | — | 0.7% | Apr 24, 2018 | Huawei AppGallery versions before 8.0.4.301 has a whitelist mechanism bypass vulnerability. An attacker may set up a mal... |
| CVE-2018-5228 | — | — | 1.2% | Apr 24, 2018 | The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbit... |
| CVE-2018-7751 | — | — | 2.4% | Apr 24, 2018 | The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of ser... |
| CVE-2018-10329 | — | — | 0.8% | Apr 24, 2018 | app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. |
| CVE-2018-10328 | — | — | 0.6% | Apr 24, 2018 | Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote at... |
| CVE-2018-10323 | — | — | 0.6% | Apr 24, 2018 | The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users... |
| CVE-2018-10322 | — | — | 0.5% | Apr 24, 2018 | The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to... |
| CVE-2018-10321 | — | — | 1.9% | Apr 24, 2018 | Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. |
| CVE-2018-10320 | — | — | 0.5% | Apr 24, 2018 | Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout. |
| CVE-2018-10319 | — | — | 0.6% | Apr 24, 2018 | Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet. |
| CVE-2018-10318 | — | — | 0.6% | Apr 24, 2018 | Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata. |
| CVE-2018-10316 | — | — | 1.1% | Apr 24, 2018 | Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a glob... |
| CVE-2018-10313 | — | — | 2.2% | Apr 24, 2018 | WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set... |
| CVE-2018-10312 | — | — | 2.5% | Apr 24, 2018 | index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. |
| CVE-2018-10311 | — | — | 2.6% | Apr 24, 2018 | A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr... |
| CVE-2018-10309 | — | — | 2.9% | Apr 24, 2018 | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. |
| CVE-2018-10305 | — | — | 1.2% | Apr 24, 2018 | The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use th... |
| CVE-2018-10303 | — | — | 2.6% | Apr 23, 2018 | A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code,... |
| CVE-2018-1106 | — | — | 0.4% | Apr 23, 2018 | An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privile... |
| CVE-2018-10302 | — | — | 3.2% | Apr 23, 2018 | A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code,... |
| CVE-2018-9921 | — | — | 1.5% | Apr 23, 2018 | In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and director... |
| CVE-2018-8880 | — | — | 14.6% | Apr 23, 2018 | Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th... |
| CVE-2018-10301 | — | — | 1.0% | Apr 23, 2018 | Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now