2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7732 | — | — | 1.1% | Mar 6, 2018 | An issue was discovered in YxtCMF 3.1. SQL Injection exists in ShitiController.class.php via the ids array parameter to ... |
| CVE-2018-7731 | — | — | 1.3% | Mar 6, 2018 | An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a... |
| CVE-2018-7730 | — | — | 1.4% | Mar 6, 2018 | An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/... |
| CVE-2018-7729 | — | — | 1.3% | Mar 6, 2018 | An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::... |
| CVE-2018-7728 | — | — | 1.4% | Mar 6, 2018 | An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a ze... |
| CVE-2018-7727 | — | — | 1.4% | Mar 6, 2018 | An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdis... |
| CVE-2018-7726 | — | — | 1.8% | Mar 6, 2018 | An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of z... |
| CVE-2018-7725 | — | — | 1.8% | Mar 6, 2018 | An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in m... |
| CVE-2018-7724 | — | — | 0.3% | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} re... |
| CVE-2018-7723 | — | — | 0.6% | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request... |
| CVE-2018-7722 | — | — | 0.6% | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploi... |
| CVE-2018-1000101 | — | — | 2.4% | Mar 6, 2018 | Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerabilit... |
| CVE-2018-1000100 | — | — | 1.1% | Mar 6, 2018 | GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2... |
| CVE-2018-7650 | — | — | 0.5% | Mar 6, 2018 | PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add... |
| CVE-2018-7307 | — | — | 0.5% | Mar 6, 2018 | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the... |
| CVE-2018-7717 | — | — | 0.7% | Mar 5, 2018 | The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.... |
| CVE-2018-7716 | — | — | 2.4% | Mar 5, 2018 | PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability with its com.privat.vpn.helper privil... |
| CVE-2018-7715 | — | — | 2.4% | Mar 5, 2018 | PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability with its com.privat.vpn.helper privil... |
| CVE-2018-7714 | — | — | 2.3% | Mar 5, 2018 | The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau... |
| CVE-2018-7713 | — | — | 2.4% | Mar 5, 2018 | The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau... |
| CVE-2018-7711 | — | — | 1.2% | Mar 5, 2018 | HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the sign... |
| CVE-2018-7493 | — | — | 1.9% | Mar 5, 2018 | CactusVPN through 6.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. Th... |
| CVE-2018-7698 | — | — | 1.1% | Mar 5, 2018 | An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlin... |
| CVE-2018-5255 | — | — | 1.1% | Mar 5, 2018 | The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of se... |
| CVE-2018-5455 | — | — | 1.6% | Mar 5, 2018 | A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series ve... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now