2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7320 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/... |
| CVE-2018-7442 | — | — | 2.1% | Feb 23, 2018 | An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the g... |
| CVE-2018-7441 | — | — | 0.3% | Feb 23, 2018 | Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or ha... |
| CVE-2018-7440 | — | — | 3.8% | Feb 23, 2018 | An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(comma... |
| CVE-2018-7439 | — | — | 2.2% | Feb 23, 2018 | An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_ne... |
| CVE-2018-7438 | — | — | 2.1% | Feb 23, 2018 | An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string funct... |
| CVE-2018-7437 | — | — | 2.1% | Feb 23, 2018 | An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST... |
| CVE-2018-7436 | — | — | 2.2% | Feb 23, 2018 | An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the p... |
| CVE-2018-7435 | — | — | 2.2% | Feb 23, 2018 | An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell funct... |
| CVE-2018-6859 | — | — | 1.8% | Feb 23, 2018 | SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter. |
| CVE-2018-6764 | — | — | 0.3% | Feb 23, 2018 | util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS ... |
| CVE-2018-0520 | — | — | 0.7% | Feb 23, 2018 | Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hi... |
| CVE-2018-0519 | — | — | 0.6% | Feb 23, 2018 | Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrar... |
| CVE-2018-0518 | — | — | 0.6% | Feb 23, 2018 | LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle ... |
| CVE-2018-7339 | — | — | 1.4% | Feb 23, 2018 | The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, w... |
| CVE-2018-6868 | — | — | 0.6% | Feb 23, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Prof... |
| CVE-2018-6867 | — | — | 0.7% | Feb 23, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter. |
| CVE-2018-6866 | — | — | 1.6% | Feb 23, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a craf... |
| CVE-2018-6489 | — | — | 1.3% | Feb 22, 2018 | XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulne... |
| CVE-2018-7319 | — | — | 2.1% | Feb 22, 2018 | SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system... |
| CVE-2018-7317 | — | — | 8.4% | Feb 22, 2018 | Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. |
| CVE-2018-7316 | — | — | 8.5% | Feb 22, 2018 | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. |
| CVE-2018-7315 | — | — | 2.8% | Feb 22, 2018 | SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast... |
| CVE-2018-7314 | — | — | 59.6% | Feb 22, 2018 | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil... |
| CVE-2018-7312 | — | — | 2.8% | Feb 22, 2018 | SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now