2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5658 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.p... |
| CVE-2018-5657 | — | — | 0.7% | Jan 13, 2018 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi... |
| CVE-2018-5656 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.... |
| CVE-2018-5655 | — | — | 0.8% | Jan 13, 2018 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj... |
| CVE-2018-5654 | — | — | 1.0% | Jan 13, 2018 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj... |
| CVE-2018-5653 | — | — | 1.0% | Jan 13, 2018 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj... |
| CVE-2018-5652 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_end... |
| CVE-2018-5651 | — | — | 0.6% | Jan 13, 2018 | An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_sta... |
| CVE-2018-5650 | — | — | 1.2% | Jan 12, 2018 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzi... |
| CVE-2018-5315 | — | — | 4.9% | Jan 12, 2018 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. |
| CVE-2018-5262 | — | — | 39.1% | Jan 12, 2018 | A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute... |
| CVE-2018-5377 | — | — | 2.1% | Jan 12, 2018 | Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action pa... |
| CVE-2018-5375 | — | — | 0.8% | Jan 12, 2018 | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action. |
| CVE-2018-5374 | — | — | 1.2% | Jan 12, 2018 | The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id... |
| CVE-2018-5373 | — | — | 1.2% | Jan 12, 2018 | The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter). |
| CVE-2018-5372 | — | — | 1.2% | Jan 12, 2018 | The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id ... |
| CVE-2018-5371 | — | — | 42.0% | Jan 12, 2018 | diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00... |
| CVE-2018-5369 | — | — | 0.6% | Jan 12, 2018 | The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php wit... |
| CVE-2018-5368 | — | — | 0.6% | Jan 12, 2018 | The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php. |
| CVE-2018-5367 | — | — | 0.8% | Jan 12, 2018 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.p... |
| CVE-2018-5366 | — | — | 0.7% | Jan 12, 2018 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.ph... |
| CVE-2018-5365 | — | — | 0.7% | Jan 12, 2018 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter... |
| CVE-2018-5364 | — | — | 0.8% | Jan 12, 2018 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] paramete... |
| CVE-2018-5363 | — | — | 0.7% | Jan 12, 2018 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enable... |
| CVE-2018-5362 | — | — | 0.8% | Jan 12, 2018 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.p... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now