2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11516 | HIGH | 8.8 | 3.6% | May 28, 2018 | The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attacker... |
| CVE-2018-11430 | — | — | 0.6% | May 28, 2018 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t... |
| CVE-2018-11309 | — | — | 2.2% | May 28, 2018 | Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated att... |
| CVE-2018-11515 | — | — | 1.7% | May 28, 2018 | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. |
| CVE-2018-11514 | — | — | 1.1% | May 28, 2018 | PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_re... |
| CVE-2018-11512 | — | — | 2.2% | May 28, 2018 | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge... |
| CVE-2018-11508 | — | — | 1.7% | May 28, 2018 | The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv... |
| CVE-2018-11507 | — | — | 1.1% | May 28, 2018 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm ... |
| CVE-2018-11506 | HIGH | 7.8 | 0.4% | May 28, 2018 | The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a de... |
| CVE-2018-6411 | — | — | 5.9% | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically ... |
| CVE-2018-6410 | — | — | 5.0% | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter. |
| CVE-2018-6409 | — | — | 14.8% | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr... |
| CVE-2018-11505 | — | — | 9.2% | May 26, 2018 | The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp... |
| CVE-2018-11504 | — | — | 1.5% | May 26, 2018 | The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of servi... |
| CVE-2018-11503 | — | — | 1.6% | May 26, 2018 | The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of s... |
| CVE-2018-11501 | — | — | 0.6% | May 26, 2018 | PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. |
| CVE-2018-11500 | — | — | 0.6% | May 26, 2018 | An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType... |
| CVE-2018-11499 | — | — | 4.0% | May 26, 2018 | A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 tha... |
| CVE-2018-11498 | — | — | 2.0% | May 26, 2018 | In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size durin... |
| CVE-2018-11496 | MEDIUM | 6.5 | 1.3% | May 26, 2018 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lr... |
| CVE-2018-11495 | — | — | 1.7% | May 26, 2018 | OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via... |
| CVE-2018-11494 | — | — | 2.4% | May 26, 2018 | The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move,... |
| CVE-2018-11493 | — | — | 0.7% | May 26, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m... |
| CVE-2018-11490 | HIGH | 8.8 | 2.5% | May 26, 2018 | The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.... |
| CVE-2018-11489 | HIGH | 8.8 | 2.6% | May 26, 2018 | The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now