2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6759 | — | — | 2.1% | Feb 6, 2018 | The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribu... |
| CVE-2018-5457 | — | — | 0.4% | Feb 6, 2018 | A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows X... |
| CVE-2018-4877 | — | — | 8.5% | Feb 6, 2018 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to ... |
| CVE-2018-1299 | — | — | 3.1% | Feb 6, 2018 | In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application... |
| CVE-2018-6758 | — | — | 2.1% | Feb 6, 2018 | The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a lar... |
| CVE-2018-6389 | — | — | 73.1% | Feb 6, 2018 | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the ... |
| CVE-2018-6291 | — | — | 0.9% | Feb 6, 2018 | WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1. |
| CVE-2018-6290 | — | — | 0.5% | Feb 6, 2018 | Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1. |
| CVE-2018-6289 | — | — | 6.7% | Feb 6, 2018 | Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1. |
| CVE-2018-6288 | — | — | 0.7% | Feb 6, 2018 | Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1. |
| CVE-2018-6656 | — | — | 0.5% | Feb 6, 2018 | Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories. |
| CVE-2018-6469 | — | — | 0.9% | Feb 6, 2018 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at... |
| CVE-2018-6468 | — | — | 0.9% | Feb 6, 2018 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at... |
| CVE-2018-6467 | — | — | 0.6% | Feb 6, 2018 | The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php. |
| CVE-2018-6466 | — | — | 0.9% | Feb 6, 2018 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at... |
| CVE-2018-6654 | — | — | 0.5% | Feb 6, 2018 | The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'a... |
| CVE-2018-6569 | — | — | 1.5% | Feb 6, 2018 | West Wind Web Server 6.x does not require authentication for /ADMIN.ASP. |
| CVE-2018-6651 | — | — | 2.2% | Feb 5, 2018 | In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin ... |
| CVE-2018-6610 | — | — | 8.1% | Feb 5, 2018 | Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request. |
| CVE-2018-6609 | — | — | 2.7% | Feb 5, 2018 | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti... |
| CVE-2018-6605 | — | — | 58.3% | Feb 5, 2018 | SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get... |
| CVE-2018-6604 | — | — | 2.7% | Feb 5, 2018 | SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail... |
| CVE-2018-6582 | — | — | 2.8% | Feb 5, 2018 | SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge... |
| CVE-2018-6635 | — | — | 1.2% | Feb 5, 2018 | System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows rem... |
| CVE-2018-6633 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now