2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9325 | — | — | 1.2% | Apr 7, 2018 | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledg... |
| CVE-2018-9330 | — | — | 0.5% | Apr 7, 2018 | register.jsp in Coremail XT3.0 allows stored XSS, as demonstrated by the third form field to a URI under register/, a di... |
| CVE-2018-9844 | — | — | 3.8% | Apr 7, 2018 | The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. |
| CVE-2018-9841 | — | — | 1.8% | Apr 7, 2018 | The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of s... |
| CVE-2018-1000157 | — | — | — | Apr 7, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9092. Reason: This candidate is a reservation ... |
| CVE-2018-9838 | — | — | 4.2% | Apr 6, 2018 | The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow w... |
| CVE-2018-9324 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9311. Reason: This candidate is a reservation ... |
| CVE-2018-9323 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9322. Reason: This candidate is a reservation ... |
| CVE-2018-9321 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9320. Reason: This candidate is a reservation ... |
| CVE-2018-9319 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9318. Reason: This candidate is a reservation ... |
| CVE-2018-9317 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9313. Reason: This candidate is a reservation ... |
| CVE-2018-9316 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9312. Reason: This candidate is a reservation ... |
| CVE-2018-9315 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9314. Reason: This candidate is a reservation ... |
| CVE-2018-7506 | — | — | 2.0% | Apr 6, 2018 | The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET ... |
| CVE-2018-1000156 | — | — | 5.6% | Apr 6, 2018 | GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_... |
| CVE-2018-9329 | — | — | — | Apr 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-1096 | — | — | 1.4% | Apr 5, 2018 | An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could ... |
| CVE-2018-9328 | — | — | 0.7% | Apr 5, 2018 | PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php. |
| CVE-2018-9233 | — | — | 1.7% | Apr 5, 2018 | Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Vir... |
| CVE-2018-4863 | — | — | 1.2% | Apr 5, 2018 | Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE... |
| CVE-2018-3624 | — | — | 1.3% | Apr 5, 2018 | Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker... |
| CVE-2018-9244 | — | — | 0.8% | Apr 5, 2018 | GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation... |
| CVE-2018-9243 | — | — | 1.0% | Apr 5, 2018 | GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation... |
| CVE-2018-7035 | — | — | 1.0% | Apr 5, 2018 | Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaS... |
| CVE-2018-1315 | — | — | 1.8% | Apr 5, 2018 | In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/mali... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now