2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7537 | — | — | 4.6% | Mar 9, 2018 | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Tru... |
| CVE-2018-7536 | — | — | 4.8% | Mar 9, 2018 | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.ur... |
| CVE-2018-7290 | — | — | 0.5% | Mar 9, 2018 | Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1. |
| CVE-2018-8002 | — | — | 8.5% | Mar 9, 2018 | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.... |
| CVE-2018-8001 | — | — | 1.3% | Mar 9, 2018 | In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attac... |
| CVE-2018-8000 | — | — | 2.9% | Mar 9, 2018 | In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfT... |
| CVE-2018-7999 | — | — | 2.3% | Mar 9, 2018 | In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRend... |
| CVE-2018-7998 | — | — | 1.9% | Mar 9, 2018 | In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate functio... |
| CVE-2018-7865 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7864 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7863 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7862 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7861 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7997 | — | — | 0.6% | Mar 9, 2018 | Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with... |
| CVE-2018-7996 | — | — | 0.7% | Mar 9, 2018 | Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter. |
| CVE-2018-0547 | — | — | 1.5% | Mar 9, 2018 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to in... |
| CVE-2018-0546 | — | — | 1.5% | Mar 9, 2018 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to in... |
| CVE-2018-0544 | — | — | 1.1% | Mar 9, 2018 | Untrusted search path vulnerability in WinShot 1.53a and earlier (Installer) allows an attacker to gain privileges via a... |
| CVE-2018-0543 | — | — | 0.9% | Mar 9, 2018 | Untrusted search path vulnerability in Jtrim 1.53c and earlier (Installer) allows an attacker to gain privileges via a T... |
| CVE-2018-0525 | — | — | 2.5% | Mar 9, 2018 | Directory traversal vulnerability in Jubatus 1.0.2 and earlier allows remote attackers to read arbitrary files via unspe... |
| CVE-2018-0524 | — | — | 2.1% | Mar 9, 2018 | Jubatus 1.0.2 and earlier allows remote code execution via unspecified vectors. |
| CVE-2018-0523 | — | — | 0.7% | Mar 9, 2018 | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified v... |
| CVE-2018-0522 | — | — | 1.4% | Mar 9, 2018 | Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a... |
| CVE-2018-0521 | — | — | 0.8% | Mar 9, 2018 | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary com... |
| CVE-2018-7995 | — | — | 0.3% | Mar 9, 2018 | Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now