2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9924 | — | — | 1.5% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp... |
| CVE-2018-9923 | — | — | 0.6% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an artic... |
| CVE-2018-9922 | — | — | 1.2% | Apr 10, 2018 | An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field tha... |
| CVE-2018-9840 | — | — | 0.4% | Apr 10, 2018 | The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feat... |
| CVE-2018-5463 | — | — | 0.4% | Apr 9, 2018 | A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME L... |
| CVE-2018-6182 | — | — | 0.7% | Apr 9, 2018 | Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE i... |
| CVE-2018-1217 | — | — | 46.6% | Apr 9, 2018 | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A... |
| CVE-2018-9864 | — | — | 1.4% | Apr 9, 2018 | The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field. |
| CVE-2018-9862 | — | — | 0.4% | Apr 9, 2018 | util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveragin... |
| CVE-2018-1308 | — | — | 20.9% | Apr 9, 2018 | This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in t... |
| CVE-2018-0556 | — | — | 0.7% | Apr 9, 2018 | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-0555 | — | — | 1.6% | Apr 9, 2018 | Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a speciall... |
| CVE-2018-0554 | — | — | 0.8% | Apr 9, 2018 | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on ... |
| CVE-2018-0553 | — | — | 0.5% | Apr 9, 2018 | The iRemoconWiFi App for Android version 4.1.7 and earlier does not verify X.509 certificates from SSL servers, which al... |
| CVE-2018-0545 | — | — | 3.1% | Apr 9, 2018 | LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-9857 | — | — | 2.3% | Apr 9, 2018 | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc... |
| CVE-2018-9856 | — | — | 0.7% | Apr 9, 2018 | Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a pe... |
| CVE-2018-6905 | — | — | 2.3% | Apr 8, 2018 | The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demons... |
| CVE-2018-9851 | — | — | 1.8% | Apr 8, 2018 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified... |
| CVE-2018-9850 | — | — | 1.9% | Apr 8, 2018 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directo... |
| CVE-2018-9848 | — | — | 2.2% | Apr 7, 2018 | In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to ex... |
| CVE-2018-9847 | — | — | 1.6% | Apr 7, 2018 | In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execu... |
| CVE-2018-9846 | — | — | 2.3% | Apr 7, 2018 | In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the ... |
| CVE-2018-9327 | — | — | 1.6% | Apr 7, 2018 | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be... |
| CVE-2018-9326 | — | — | 2.0% | Apr 7, 2018 | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now