2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-6902PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action.
CVE-2018-6900PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page.
CVE-2018-6879PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allo...
CVE-2018-6870Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature.
CVE-2018-5254Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path ...
CVE-2018-10063The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that ...
CVE-2018-10074The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows loc...
CVE-2018-10073joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
CVE-2018-10072windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538...
CVE-2018-10071windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538...
CVE-2018-10068The jDownloads extension before 3.2.59 for Joomla! has XSS.
CVE-2018-10059Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] in...
CVE-2018-9843The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute ...
CVE-2018-9842CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay...
CVE-2018-9155Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we...
CVE-2018-9118exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct...
CVE-2018-9860An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC...
CVE-2018-8117A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to r...
CVE-2018-8116A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Comp...
CVE-2018-1037An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized...
CVE-2018-1034An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-1032An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-1030A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj...
CVE-2018-1028A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted emb...
CVE-2018-1026A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now