2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-6759The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribu...
CVE-2018-5457A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows X...
CVE-2018-4877A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to ...
CVE-2018-1299In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application...
CVE-2018-6758The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a lar...
CVE-2018-6389In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the ...
CVE-2018-6291WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6290Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6289Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6288Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
CVE-2018-6656Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
CVE-2018-6469A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at...
CVE-2018-6468A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at...
CVE-2018-6467The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.
CVE-2018-6466A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at...
CVE-2018-6654The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'a...
CVE-2018-6569West Wind Web Server 6.x does not require authentication for /ADMIN.ASP.
CVE-2018-6651In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin ...
CVE-2018-6610Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
CVE-2018-6609SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti...
CVE-2018-6605SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get...
CVE-2018-6604SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail...
CVE-2018-6582SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge...
CVE-2018-6635System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows rem...
CVE-2018-6633In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now