2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5691 | — | — | 0.7% | Jan 14, 2018 | SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` modu... |
| CVE-2018-5690 | — | — | 0.9% | Jan 14, 2018 | Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inje... |
| CVE-2018-5689 | — | — | 0.9% | Jan 14, 2018 | Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to injec... |
| CVE-2018-5687 | — | — | 0.5% | Jan 14, 2018 | NewsBee allows XSS via the Company Name field in the Settings under admin/admin.php. |
| CVE-2018-5685 | — | — | 1.9% | Jan 14, 2018 | In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Re... |
| CVE-2018-5684 | — | — | 1.2% | Jan 14, 2018 | In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Re... |
| CVE-2018-5360 | — | — | 1.8% | Jan 14, 2018 | LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadT... |
| CVE-2018-0486 | — | — | 1.5% | Jan 13, 2018 | Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products,... |
| CVE-2018-5682 | — | — | 0.9% | Jan 13, 2018 | PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produ... |
| CVE-2018-5681 | — | — | 0.5% | Jan 13, 2018 | PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen. |
| CVE-2018-5673 | — | — | 0.8% | Jan 13, 2018 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. |
| CVE-2018-5672 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_f... |
| CVE-2018-5671 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_... |
| CVE-2018-5670 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_c... |
| CVE-2018-5669 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.ph... |
| CVE-2018-5668 | — | — | 0.7% | Jan 13, 2018 | An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general... |
| CVE-2018-5667 | — | — | 0.7% | Jan 13, 2018 | An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general... |
| CVE-2018-5666 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5665 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5664 | — | — | 0.7% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5663 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5662 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5661 | — | — | 0.7% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5660 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5659 | — | — | 0.7% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now