2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5311 | — | — | 0.6% | Jan 9, 2018 | The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the... |
| CVE-2018-5310 | — | — | 1.6% | Jan 9, 2018 | In the "Media from FTP" plugin before 9.85 for WordPress, Directory Traversal exists via the searchdir parameter to the ... |
| CVE-2018-5309 | — | — | 1.1% | Jan 9, 2018 | In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/P... |
| CVE-2018-5308 | — | — | 1.3% | Jan 9, 2018 | PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStr... |
| CVE-2018-5263 | — | — | 1.6% | Jan 8, 2018 | The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. |
| CVE-2018-5301 | — | — | 0.4% | Jan 8, 2018 | Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of... |
| CVE-2018-5283 | — | — | 1.7% | Jan 8, 2018 | The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/ass... |
| CVE-2018-5282 | — | — | 1.5% | Jan 8, 2018 | Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie... |
| CVE-2018-5259 | — | — | 2.0% | Jan 8, 2018 | Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modifie... |
| CVE-2018-5298 | — | — | 0.4% | Jan 8, 2018 | In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with stat... |
| CVE-2018-5296 | — | — | 1.0% | Jan 8, 2018 | In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParse... |
| CVE-2018-5295 | — | — | 1.0% | Jan 8, 2018 | In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStream... |
| CVE-2018-5294 | — | — | 1.9% | Jan 8, 2018 | In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/r... |
| CVE-2018-5293 | — | — | 1.3% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste... |
| CVE-2018-5292 | — | — | 1.3% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste... |
| CVE-2018-5291 | — | — | 3.7% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the ... |
| CVE-2018-5290 | — | — | 3.7% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the ... |
| CVE-2018-5289 | — | — | 3.7% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the ... |
| CVE-2018-5288 | — | — | 1.4% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste... |
| CVE-2018-5287 | — | — | 3.7% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the ... |
| CVE-2018-5286 | — | — | 1.3% | Jan 8, 2018 | The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste... |
| CVE-2018-5285 | — | — | 0.7% | Jan 8, 2018 | The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. |
| CVE-2018-5284 | — | — | 0.8% | Jan 8, 2018 | The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php. |
| CVE-2018-5277 | — | — | 0.4% | Jan 8, 2018 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-5276 | — | — | 0.4% | Jan 8, 2018 | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now