2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11516HIGH8.8The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attacker...
CVE-2018-11430An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t...
CVE-2018-11309Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated att...
CVE-2018-11515The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
CVE-2018-11514PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_re...
CVE-2018-11512Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge...
CVE-2018-11508The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv...
CVE-2018-11507An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm ...
CVE-2018-11506HIGH7.8The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a de...
CVE-2018-6411An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically ...
CVE-2018-6410An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CVE-2018-6409An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr...
CVE-2018-11505The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp...
CVE-2018-11504The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of servi...
CVE-2018-11503The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of s...
CVE-2018-11501PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
CVE-2018-11500An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType...
CVE-2018-11499A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 tha...
CVE-2018-11498In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size durin...
CVE-2018-11496MEDIUM6.5In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lr...
CVE-2018-11495OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via...
CVE-2018-11494The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move,...
CVE-2018-11493An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m...
CVE-2018-11490HIGH8.8The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0....
CVE-2018-11489HIGH8.8The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0....

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now