2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6902 | — | — | 0.5% | Apr 12, 2018 | PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action. |
| CVE-2018-6900 | — | — | 0.5% | Apr 12, 2018 | PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page. |
| CVE-2018-6879 | — | — | 1.1% | Apr 12, 2018 | PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allo... |
| CVE-2018-6870 | — | — | 0.7% | Apr 12, 2018 | Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature. |
| CVE-2018-5254 | — | — | 1.3% | Apr 12, 2018 | Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path ... |
| CVE-2018-10063 | — | — | 9.6% | Apr 12, 2018 | The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that ... |
| CVE-2018-10074 | — | — | 0.3% | Apr 12, 2018 | The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows loc... |
| CVE-2018-10073 | — | — | 0.6% | Apr 12, 2018 | joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. |
| CVE-2018-10072 | — | — | 0.4% | Apr 12, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538... |
| CVE-2018-10071 | — | — | 0.4% | Apr 12, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538... |
| CVE-2018-10068 | — | — | 4.1% | Apr 12, 2018 | The jDownloads extension before 3.2.59 for Joomla! has XSS. |
| CVE-2018-10059 | — | — | 1.2% | Apr 12, 2018 | Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] in... |
| CVE-2018-9843 | — | — | 17.3% | Apr 12, 2018 | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute ... |
| CVE-2018-9842 | — | — | 14.1% | Apr 12, 2018 | CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay... |
| CVE-2018-9155 | — | — | 1.2% | Apr 12, 2018 | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we... |
| CVE-2018-9118 | — | — | 48.2% | Apr 12, 2018 | exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct... |
| CVE-2018-9860 | — | — | 1.4% | Apr 12, 2018 | An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC... |
| CVE-2018-8117 | — | — | 1.2% | Apr 12, 2018 | A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to r... |
| CVE-2018-8116 | — | — | 1.4% | Apr 12, 2018 | A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Comp... |
| CVE-2018-1037 | — | — | 5.9% | Apr 12, 2018 | An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized... |
| CVE-2018-1034 | — | — | 2.3% | Apr 12, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-1032 | — | — | 2.3% | Apr 12, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-1030 | — | — | 24.3% | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj... |
| CVE-2018-1028 | — | — | 19.1% | Apr 12, 2018 | A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted emb... |
| CVE-2018-1026 | — | — | 41.3% | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now