2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3592 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MD... |
| CVE-2018-3591 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MD... |
| CVE-2018-3590 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD ... |
| CVE-2018-3589 | — | — | 1.4% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile MDM9650, MDM9655, SD 835, SD 845, SD 850... |
| CVE-2018-9992 | — | — | 0.5% | Apr 11, 2018 | Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ scre... |
| CVE-2018-9991 | — | — | 0.5% | Apr 11, 2018 | Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter. |
| CVE-2018-7660 | — | — | 0.5% | Apr 11, 2018 | In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially b... |
| CVE-2018-7659 | — | — | 0.5% | Apr 11, 2018 | In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be e... |
| CVE-2018-10016 | — | — | 1.1% | Apr 11, 2018 | Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the expr5 function in asm/eval.c via a malforme... |
| CVE-2018-10001 | — | — | 2.4% | Apr 11, 2018 | The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of... |
| CVE-2018-10000 | — | — | 0.6% | Apr 11, 2018 | The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to... |
| CVE-2018-9996 | — | — | 1.3% | Apr 10, 2018 | An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in... |
| CVE-2018-9995 | — | — | 83.2% | Apr 10, 2018 | TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L... |
| CVE-2018-9993 | — | — | 0.5% | Apr 10, 2018 | YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page). |
| CVE-2018-9985 | — | — | 0.7% | Apr 10, 2018 | The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator. |
| CVE-2018-9918 | — | — | 1.7% | Apr 10, 2018 | libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing r... |
| CVE-2018-9038 | — | — | 9.8% | Apr 10, 2018 | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo... |
| CVE-2018-9037 | — | — | 2.9% | Apr 10, 2018 | Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extrac... |
| CVE-2018-8772 | — | — | 1.8% | Apr 10, 2018 | Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. |
| CVE-2018-5227 | — | — | 0.6% | Apr 10, 2018 | Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attac... |
| CVE-2018-9934 | — | — | 1.4% | Apr 10, 2018 | The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a ... |
| CVE-2018-9928 | — | — | 0.8% | Apr 10, 2018 | Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web scri... |
| CVE-2018-9927 | — | — | 0.7% | Apr 10, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=me... |
| CVE-2018-9926 | — | — | 3.1% | Apr 10, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=... |
| CVE-2018-9925 | — | — | 0.6% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&d... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now