2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-7320In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/...
CVE-2018-7442An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the g...
CVE-2018-7441Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or ha...
CVE-2018-7440An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(comma...
CVE-2018-7439An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_ne...
CVE-2018-7438An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string funct...
CVE-2018-7437An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST...
CVE-2018-7436An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the p...
CVE-2018-7435An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell funct...
CVE-2018-6859SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.
CVE-2018-6764util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS ...
CVE-2018-0520Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hi...
CVE-2018-0519Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrar...
CVE-2018-0518LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle ...
CVE-2018-7339The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, w...
CVE-2018-6868Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Prof...
CVE-2018-6867Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter.
CVE-2018-6866Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a craf...
CVE-2018-6489XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulne...
CVE-2018-7319SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system...
CVE-2018-7317Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
CVE-2018-7316Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
CVE-2018-7315SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast...
CVE-2018-7314SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil...
CVE-2018-7312SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now