2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8809 | — | — | 1.1% | Mar 20, 2018 | In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers co... |
| CVE-2018-8808 | — | — | 1.1% | Mar 20, 2018 | In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers co... |
| CVE-2018-8807 | — | — | 1.7% | Mar 20, 2018 | In libming 0.4.8, these is a use-after-free in the function decompileCALLFUNCTION of decompile.c. Remote attackers could... |
| CVE-2018-8806 | — | — | 1.5% | Mar 20, 2018 | In libming 0.4.8, there is a use-after-free in the decompileArithmeticOp function of decompile.c. Remote attackers could... |
| CVE-2018-8805 | — | — | 0.7% | Mar 20, 2018 | Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\de... |
| CVE-2018-8804 | — | — | 3.8% | Mar 20, 2018 | WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCo... |
| CVE-2018-7262 | — | — | 3.0% | Mar 19, 2018 | In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't han... |
| CVE-2018-5233 | — | — | 3.4% | Mar 19, 2018 | Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote ... |
| CVE-2018-8732 | — | — | 1.7% | Mar 19, 2018 | Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H... |
| CVE-2018-1226 | — | — | — | Mar 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-1225 | — | — | — | Mar 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-1224 | — | — | — | Mar 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-1218 | — | — | 14.0% | Mar 19, 2018 | In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the '... |
| CVE-2018-1197 | — | — | 0.6% | Mar 19, 2018 | In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are a... |
| CVE-2018-1196 | — | — | 1.2% | Mar 19, 2018 | Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d lin... |
| CVE-2018-8761 | — | — | 0.9% | Mar 19, 2018 | protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a log... |
| CVE-2018-7422 | — | — | 63.1% | Mar 19, 2018 | A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re... |
| CVE-2018-6843 | — | — | 1.2% | Mar 19, 2018 | Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface. |
| CVE-2018-6842 | — | — | 0.6% | Mar 19, 2018 | Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a syst... |
| CVE-2018-8769 | — | — | 0.9% | Mar 18, 2018 | elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_... |
| CVE-2018-8768 | — | — | 1.1% | Mar 18, 2018 | In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in th... |
| CVE-2018-8767 | — | — | 0.6% | Mar 18, 2018 | joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter. |
| CVE-2018-8766 | — | — | 3.4% | Mar 18, 2018 | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, r... |
| CVE-2018-8765 | — | — | 0.4% | Mar 18, 2018 | In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-8756 | — | — | 3.4% | Mar 18, 2018 | Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary cod... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now