2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6473 | — | — | 0.3% | Jan 31, 2018 | In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of ... |
| CVE-2018-6472 | — | — | 0.3% | Jan 31, 2018 | In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of ... |
| CVE-2018-6471 | — | — | 0.3% | Jan 31, 2018 | In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of ... |
| CVE-2018-6465 | — | — | 1.7% | Jan 31, 2018 | The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-... |
| CVE-2018-6462 | — | — | 2.5% | Jan 31, 2018 | Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calc... |
| CVE-2018-5996 | — | — | 2.9% | Jan 31, 2018 | Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead ... |
| CVE-2018-5701 | — | — | 18.5% | Jan 31, 2018 | In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi... |
| CVE-2018-6460 | — | — | 11.2% | Jan 31, 2018 | Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sen... |
| CVE-2018-6384 | — | — | 0.8% | Jan 31, 2018 | Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute ar... |
| CVE-2018-1000001 | — | — | 13.6% | Jan 31, 2018 | In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th... |
| CVE-2018-6412 | — | — | 2.4% | Jan 31, 2018 | In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer sign... |
| CVE-2018-6408 | — | — | 0.6% | Jan 30, 2018 | An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrat... |
| CVE-2018-6407 | — | — | 32.8% | Jan 30, 2018 | An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a devic... |
| CVE-2018-6406 | — | — | 2.0% | Jan 30, 2018 | The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child... |
| CVE-2018-6194 | — | — | 1.0% | Jan 30, 2018 | A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plug... |
| CVE-2018-5441 | — | — | 0.3% | Jan 30, 2018 | An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to ... |
| CVE-2018-6380 | — | — | 2.0% | Jan 30, 2018 | In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. |
| CVE-2018-6379 | — | — | 2.0% | Jan 30, 2018 | In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability. |
| CVE-2018-6377 | — | — | 58.1% | Jan 30, 2018 | In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types,... |
| CVE-2018-6376 | — | — | 4.8% | Jan 30, 2018 | In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerabilit... |
| CVE-2018-6355 | — | — | 0.7% | Jan 30, 2018 | /goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site ... |
| CVE-2018-6398 | — | — | 2.7% | Jan 30, 2018 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. |
| CVE-2018-6397 | — | — | 12.2% | Jan 30, 2018 | Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter. |
| CVE-2018-6395 | — | — | 2.7% | Jan 30, 2018 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. |
| CVE-2018-6382 | — | — | 0.5% | Jan 30, 2018 | MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parame... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now