2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0532 | — | — | 0.9% | Apr 16, 2018 | Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of... |
| CVE-2018-0531 | — | — | 0.9% | Apr 16, 2018 | Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an acce... |
| CVE-2018-0530 | — | — | 1.4% | Apr 16, 2018 | SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitra... |
| CVE-2018-9169 | — | — | 0.5% | Apr 16, 2018 | Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be access... |
| CVE-2018-9153 | — | — | 1.2% | Apr 16, 2018 | The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id para... |
| CVE-2018-10122 | — | — | 2.2% | Apr 16, 2018 | QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) pro1.6 allows remote attackers to read arbitr... |
| CVE-2018-10121 | — | — | 0.7% | Apr 16, 2018 | plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the... |
| CVE-2018-10120 | — | — | 2.1% | Apr 16, 2018 | The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.... |
| CVE-2018-10119 | — | — | 2.0% | Apr 16, 2018 | sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type ... |
| CVE-2018-10118 | — | — | 2.9% | Apr 16, 2018 | Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI... |
| CVE-2018-10117 | — | — | 0.6% | Apr 16, 2018 | An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admin... |
| CVE-2018-10114 | — | — | 1.9% | Apr 16, 2018 | An issue was discovered in GEGL through 0.3.32. The gegl_buffer_iterate_read_simple function in buffer/gegl-buffer-acces... |
| CVE-2018-10113 | — | — | 1.3% | Apr 16, 2018 | An issue was discovered in GEGL through 0.3.32. The process function in operations/external/ppm-load.c has unbounded mem... |
| CVE-2018-10112 | — | — | 1.5% | Apr 16, 2018 | An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_swap_constructed function in buffer/gegl-tile-back... |
| CVE-2018-10111 | — | — | 1.3% | Apr 16, 2018 | An issue was discovered in GEGL through 0.3.32. The render_rectangle function in process/gegl-processor.c has unbounded ... |
| CVE-2018-10109 | — | — | 2.2% | Apr 16, 2018 | Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload ... |
| CVE-2018-10108 | — | — | 1.2% | Apr 16, 2018 | D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn param... |
| CVE-2018-10107 | — | — | 1.2% | Apr 16, 2018 | D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parame... |
| CVE-2018-10106 | — | — | 2.0% | Apr 16, 2018 | D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and in... |
| CVE-2018-10102 | — | — | 5.3% | Apr 16, 2018 | Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a... |
| CVE-2018-10101 | — | — | 3.3% | Apr 16, 2018 | Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPres... |
| CVE-2018-10100 | — | — | 3.4% | Apr 16, 2018 | Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. |
| CVE-2018-10097 | — | — | 1.6% | Apr 16, 2018 | XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter. |
| CVE-2018-1000170 | — | — | 0.9% | Apr 16, 2018 | A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly... |
| CVE-2018-1000169 | — | — | 1.4% | Apr 16, 2018 | An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLIComma... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now