2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0552 | — | — | 1.0% | Mar 22, 2018 | Untrusted search path vulnerability in The installer of PhishWall Client Firefox and Chrome edition for Windows Ver. 5.1... |
| CVE-2018-0542 | — | — | 2.3% | Mar 22, 2018 | Directory traversal vulnerability in WebProxy version 1.7.8 allows an attacker to read arbitrary files via unspecified v... |
| CVE-2018-0541 | — | — | 3.2% | Mar 22, 2018 | Buffer overflow in Tiny FTP Daemon Ver0.52d allows an attacker to cause a denial-of-service (DoS) condition or execute a... |
| CVE-2018-0540 | — | — | 1.0% | Mar 22, 2018 | Untrusted search path vulnerability in ViX version 2.21.148.0 allows an attacker to gain privileges via a Trojan horse D... |
| CVE-2018-0539 | — | — | 2.7% | Mar 22, 2018 | QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors. |
| CVE-2018-0538 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-0537 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-0536 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-0535 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in PHP 2chBBS version bbs18c allows an attacker to inject arbitrary web script or HTM... |
| CVE-2018-0534 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in ArsenoL Version 0.5 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-8909 | — | — | 2.0% | Mar 22, 2018 | The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads direc... |
| CVE-2018-8899 | — | — | 1.3% | Mar 22, 2018 | IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorizati... |
| CVE-2018-8906 | — | — | 0.7% | Mar 22, 2018 | dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishan... |
| CVE-2018-8904 | — | — | 0.4% | Mar 22, 2018 | In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users ... |
| CVE-2018-8896 | — | — | 0.4% | Mar 22, 2018 | In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) o... |
| CVE-2018-8895 | — | — | 0.4% | Mar 22, 2018 | In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) o... |
| CVE-2018-8894 | — | — | 0.4% | Mar 22, 2018 | In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or... |
| CVE-2018-7525 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untru... |
| CVE-2018-7523 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability. |
| CVE-2018-7521 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parse... |
| CVE-2018-7517 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability... |
| CVE-2018-1230 | — | — | 0.7% | Mar 21, 2018 | Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticat... |
| CVE-2018-1229 | — | — | 0.8% | Mar 21, 2018 | Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthentic... |
| CVE-2018-8074 | — | — | 1.5% | Mar 21, 2018 | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 ... |
| CVE-2018-8073 | — | — | 1.6% | Mar 21, 2018 | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now