2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-10300Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows re...
CVE-2018-4847A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection ...
CVE-2018-10234Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "A...
CVE-2018-10233The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site reques...
CVE-2018-10299An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), th...
CVE-2018-10298Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_porta...
CVE-2018-10297Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IM...
CVE-2018-10296MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.
CVE-2018-10295ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.
CVE-2018-9245The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a...
CVE-2018-10286The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th...
CVE-2018-10285The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any...
CVE-2018-10268An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avat...
CVE-2018-10267WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
CVE-2018-10266BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&a...
CVE-2018-10265An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the a...
CVE-2018-10284Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.
CVE-2018-10283CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.
CVE-2018-10254Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Rem...
CVE-2018-10253Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
CVE-2018-9059Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code ...
CVE-2018-7747Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re...
CVE-2018-10176Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
CVE-2018-10175Digital Guardian Management Console 7.1.2.0015 has an XXE issue.
CVE-2018-10174Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files vi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now