2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6593 | — | — | 1.1% | Feb 3, 2018 | An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows ... |
| CVE-2018-6538 | — | — | — | Feb 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-1184 | — | — | 1.1% | Feb 3, 2018 | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0... |
| CVE-2018-6594 | — | — | 2.1% | Feb 3, 2018 | lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers ... |
| CVE-2018-6319 | — | — | 0.3% | Feb 2, 2018 | In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. T... |
| CVE-2018-6318 | — | — | 1.1% | Feb 2, 2018 | In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ranso... |
| CVE-2018-6317 | — | — | 44.3% | Feb 2, 2018 | The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin... |
| CVE-2018-5261 | — | — | 0.5% | Feb 2, 2018 | An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the hand... |
| CVE-2018-6581 | — | — | 2.7% | Feb 2, 2018 | SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username par... |
| CVE-2018-6580 | — | — | 36.9% | Feb 2, 2018 | Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true... |
| CVE-2018-6579 | — | — | 3.9% | Feb 2, 2018 | SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. |
| CVE-2018-6578 | — | — | 3.9% | Feb 2, 2018 | SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task... |
| CVE-2018-6577 | — | — | 2.0% | Feb 2, 2018 | SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta... |
| CVE-2018-6576 | — | — | 2.7% | Feb 2, 2018 | SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter. |
| CVE-2018-6575 | — | — | 2.7% | Feb 2, 2018 | SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. |
| CVE-2018-6561 | — | — | 1.1% | Feb 2, 2018 | dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. |
| CVE-2018-6560 | — | — | 0.4% | Feb 2, 2018 | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the... |
| CVE-2018-6551 | — | — | 2.2% | Feb 2, 2018 | The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in v... |
| CVE-2018-6550 | — | — | 0.7% | Feb 2, 2018 | Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/... |
| CVE-2018-6548 | — | — | 1.4% | Feb 2, 2018 | A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, i... |
| CVE-2018-6545 | — | — | 1.6% | Feb 2, 2018 | Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. ... |
| CVE-2018-6544 | — | — | 1.6% | Feb 2, 2018 | pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore r... |
| CVE-2018-6543 | — | — | 2.3% | Feb 2, 2018 | In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which resu... |
| CVE-2018-6542 | — | — | 1.2% | Feb 2, 2018 | In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned a... |
| CVE-2018-6541 | — | — | 2.3% | Feb 2, 2018 | In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local e... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now