2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5080In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or poss...
CVE-2018-5079In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or poss...
CVE-2018-5078Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.
CVE-2018-5077Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.
CVE-2018-5076Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter.
CVE-2018-5075Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter.
CVE-2018-5074Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter.
CVE-2018-5073Online Ticket Booking has CSRF via admin/movieedit.php.
CVE-2018-5072Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.
CVE-2018-4868The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of se...
CVE-2018-4862In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could refe...
CVE-2018-3814Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and ...
CVE-2018-3813getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by...
CVE-2018-3811SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica...
CVE-2018-3810Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now