2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7265 | — | — | 0.9% | Feb 20, 2018 | Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS. |
| CVE-2018-7263 | — | — | 2.5% | Feb 20, 2018 | The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial... |
| CVE-2018-5477 | — | — | 1.3% | Feb 20, 2018 | An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Appli... |
| CVE-2018-7205 | — | — | 0.9% | Feb 20, 2018 | Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote a... |
| CVE-2018-7046 | — | — | 5.7% | Feb 20, 2018 | Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary op... |
| CVE-2018-6941 | — | — | 3.6% | Feb 20, 2018 | A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot... |
| CVE-2018-6940 | — | — | 2.9% | Feb 20, 2018 | A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote... |
| CVE-2018-6459 | — | — | 1.1% | Feb 20, 2018 | The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote... |
| CVE-2018-7259 | — | — | 1.0% | Feb 20, 2018 | The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://insta... |
| CVE-2018-7254 | — | — | 10.3% | Feb 19, 2018 | The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of... |
| CVE-2018-7253 | — | — | 3.0% | Feb 19, 2018 | The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denia... |
| CVE-2018-7251 | — | — | 72.6% | Feb 19, 2018 | An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain... |
| CVE-2018-5763 | — | — | 1.1% | Feb 19, 2018 | An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafte... |
| CVE-2018-6592 | — | — | 0.3% | Feb 19, 2018 | Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by lev... |
| CVE-2018-7247 | — | — | 2.5% | Feb 19, 2018 | An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) c... |
| CVE-2018-5439 | — | — | 4.2% | Feb 19, 2018 | A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attack... |
| CVE-2018-7226 | — | — | 2.4% | Feb 19, 2018 | An issue was discovered in vcSetXCutTextProc() in VNConsole.c in LinuxVNC and VNCommand from the LibVNC/vncterm distribu... |
| CVE-2018-7225 | — | — | 6.4% | Feb 19, 2018 | An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize... |
| CVE-2018-7219 | — | — | 0.5% | Feb 19, 2018 | application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or addin... |
| CVE-2018-6591 | — | — | 1.1% | Feb 19, 2018 | Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficul... |
| CVE-2018-1411 | — | — | 0.4% | Feb 19, 2018 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ... |
| CVE-2018-1410 | — | — | 0.4% | Feb 19, 2018 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ... |
| CVE-2018-1409 | — | — | 0.4% | Feb 19, 2018 | IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the ... |
| CVE-2018-6024 | — | — | 3.2% | Feb 18, 2018 | SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter. |
| CVE-2018-7217 | — | — | 1.9% | Feb 18, 2018 | In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now