2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6393 | — | — | 2.2% | Jan 29, 2018 | FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order param... |
| CVE-2018-6392 | — | — | 1.7% | Jan 29, 2018 | The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denia... |
| CVE-2018-6391 | — | — | 1.0% | Jan 29, 2018 | A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker... |
| CVE-2018-6388 | — | — | 6.0% | Jan 29, 2018 | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands... |
| CVE-2018-6387 | — | — | 1.8% | Jan 29, 2018 | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardc... |
| CVE-2018-6381 | — | — | 1.7% | Jan 29, 2018 | In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56... |
| CVE-2018-1364 | — | — | 2.4% | Jan 29, 2018 | IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data... |
| CVE-2018-6367 | — | — | 3.1% | Jan 29, 2018 | SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame... |
| CVE-2018-6365 | — | — | 3.1% | Jan 29, 2018 | SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. |
| CVE-2018-6364 | — | — | 3.1% | Jan 29, 2018 | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. |
| CVE-2018-6008 | — | — | 37.4% | Jan 29, 2018 | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter... |
| CVE-2018-6007 | — | — | 2.3% | Jan 29, 2018 | CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket. |
| CVE-2018-5720 | — | — | 2.8% | Jan 29, 2018 | An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A C... |
| CVE-2018-6360 | — | — | 2.6% | Jan 28, 2018 | mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML docum... |
| CVE-2018-6359 | — | — | 2.5% | Jan 27, 2018 | The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow ... |
| CVE-2018-6358 | — | — | 1.9% | Jan 27, 2018 | The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, w... |
| CVE-2018-6357 | — | — | 0.7% | Jan 27, 2018 | The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordP... |
| CVE-2018-6354 | — | — | 0.8% | Jan 27, 2018 | templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter. |
| CVE-2018-6353 | — | — | 0.5% | Jan 27, 2018 | The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1... |
| CVE-2018-6352 | — | — | 1.0% | Jan 27, 2018 | In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. R... |
| CVE-2018-6015 | — | — | 3.3% | Jan 26, 2018 | An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST... |
| CVE-2018-5750 | — | — | 0.5% | Jan 26, 2018 | The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain ... |
| CVE-2018-0507 | — | — | 0.9% | Jan 26, 2018 | Untrusted search path vulnerability in FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.11 and earlier versions, FLE... |
| CVE-2018-0506 | — | — | 2.3% | Jan 26, 2018 | Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-6323 | — | — | 5.9% | Jan 26, 2018 | The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now